CVE-2017-6594 PUBLISHED

The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.

EPSS 0.25% · 48.0th percentile

Risk Scores

EPSS Score
0.25%
48.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSheimdal0, 1.6~rc2+dfsg-10ubuntu1, 1.7~git20150920+dfsg-4ubuntu1
Ubuntu:Pro:14.04:LTSheimdal1.6~git20131207+dfsg-1ubuntu1.2+esm3, 0, 1.6~git20131207+dfsg-1ubuntu1.2+esm4

Timeline

References

Open in Interactive Console →