ALPINE-CVE-2017-11103
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.13 | heimdal | 1.3.1-r5, 1.3.1-r4, 1.3.1-r3 |
| Alpine:v3.6 | heimdal | 1.6, 0, 0 |
| Alpine:v3.17 | heimdal | 1.2.1-r4, 0, 7.1.0-r1 |
| Alpine:v3.15 | heimdal | 1.2.1-r0, 1.2.1-r1, 1.2.1-r2 |
| Alpine:v3.23 | heimdal | 1.3.1-r0, 0, 7.1.0-r1 |
| Alpine:v3.20 | heimdal | 1.4-r6, 1.4-r4, 1.4-r11 |
| Alpine:v3.6 | samba | 3.3.4-r0, 3.2.8-r1, 3.2.8-r0 |
| Alpine:v3.16 | heimdal | 1.4-r6, 0, 7.1.0-r1 |
| Alpine:v3.4 | samba | 4.2.1-r0, 4.2.1-r2, 4.2.1-r1 |
| Alpine:v3.9 | heimdal | 1.2.1-r2, 1.2.1-r3, 1.2.1-r4 |
| Alpine:v3.4 | heimdal | 1.4-r11, 1.2.1-r4, 1.2.1-r2 |
| Alpine:v3.8 | heimdal | 1.3.1-r3, 0, 7.1.0-r1 |
| Alpine:v3.10 | heimdal | 1.3.1-r4, 1.2.1-r3, 1.2.1-r4 |
| Alpine:v3.19 | heimdal | 1.4-r8, 1.4-r9, 1.5.2-r4 |
| Alpine:v3.21 | heimdal | 1.5-r2, 1.5.2-r4, 1.5.2-r5 |
| Alpine:v3.5 | samba | 4.1.8-r0, 4.1.7-r0, 4.1.6-r0 |
| Alpine:v3.7 | heimdal | 1.4-r6, 0, 7.1.0-r1 |
| Alpine:v3.5 | heimdal | 1.4-r2, 1.4-r3, 1.4-r5 |
| Alpine:v3.22 | heimdal | 1.4-r1, 1.4-r10, 1.4-r11 |
| Alpine:v3.3 | samba | 3.5.11-r0, 3.5.10-r0, 3.4.7-r1 |
…and 6 more
Timeline
- Jul 13, 2017 CVE Published
- Apr 30, 2026 Distribution Patch
- Jun 15, 2026 CVE Updated