CVE-2019-12098 PUBLISHED

In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.

EPSS 4.72% · 89.3th percentile

Risk Scores

EPSS Score
4.72%
89.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSheimdal7.5.0+dfsg-1, 7.4.0.dfsg.1-2, 0
Ubuntu:Pro:14.04:LTSheimdal1.6~git20131207+dfsg-1ubuntu1, 1.6~git20131207+dfsg-1ubuntu1.1, 1.6~git20131207+dfsg-1ubuntu1.2
Ubuntu:Pro:16.04:LTSheimdal1.7~git20150920+dfsg-4ubuntu1.16.04.1, 1.7~git20150920+dfsg-4ubuntu1, 1.6~rc2+dfsg-10ubuntu1

Timeline

References

Open in Interactive Console →