Back to search
CVE-2019-12098
Published: May 15, 2019
Modified: Apr 15, 2026
PUBLISHED
Description
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/heimdal/heimdal/releases/tag/heimdal-7.6.0
x_refsource_MISC
http://www.h5l.org/pipermail/heimdal-announce/2019-May/000009.html
x_refsource_CONFIRM
https://github.com/heimdal/heimdal/compare/3e58559...bbafe72
x_refsource_MISC
20190603 [SECURITY] [DSA 4455-1] heimdal security update
mailing-list
x_refsource_BUGTRAQ
DSA-4455
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2019:1682
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1688
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1888
vendor-advisory
x_refsource_SUSE
FEDORA-2019-f3046b6bfb
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-2fa7d6405b
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now