CVE Database
/

CVE-2017-11103

Back to search

CVE-2017-11103

Published: Jul 13, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-3912
vendor-advisory
x_refsource_DEBIAN
FreeBSD-SA-17:05
vendor-advisory
x_refsource_FREEBSD
99551
vdb-entry
x_refsource_BID
1039427
vdb-entry
x_refsource_SECTRACK
1038876
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now