VDB

DEBIAN-CVE-2022-45142

DEBIAN-CVE-2022-45142 PUBLISHED CVSS 7.5 HIGH

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:14heimdal0, 0, 0
Debian:13heimdal0, 0, 0
Debian:12heimdal0, 0, 0
Debian:11heimdal7.7.0+dfsg, 0, 7.7.0+dfsg-2

Timeline

  • Mar 6, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›