VDB

CVE-2019-12098

CVE-2019-12098 PUBLISHED

In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.

EPSS 2.12% · 84.5th percentile

Risk Scores

EPSS Score
2.12%
84.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSheimdal0, *, 7.4.0.dfsg.1-2
Ubuntu:Pro:14.04:LTSheimdal*, 1.6~git20120403+dfsg1-3ubuntu0.1, 1.6~git20131207+dfsg-1ubuntu1
Ubuntu:Pro:16.04:LTSheimdal*, 1.7~git20150920+dfsg-4ubuntu1.16.04.1, 1.7~git20150920+dfsg-4ubuntu1

Timeline

  • May 15, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›