VDB

GCVE-110-CERTCC-2022-730793

GCVE-110-CERTCC-2022-730793
Advisory Published
Vulnetix · Advisory published October 7, 2022
### Overview The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash. ### Description **CVE-2022-3116** A flawed logical condition in lib/gssapi/spnego/accept_sec_context.c allows a malicious actor to remotely trigger a NULL pointer dereference using a crafted negTokenInit token. ### Impact An attacker can use a specially crafted network packet to cause a vulnerable application to crash. ### Solution The latest version of code in the Heimdal master branch fixes the issue. However, the current stable release 7.7.0 does not include the fix. ### Acknowledgements Thanks to Internet Systems Consortium for reporting the vulnerability. This document was written by Kevin Stephens.

Browse GCVE Records

77,895 records in the GCVE database · Updated August 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›