VDB
GCVE-VVD-MAGEIA-2017-308
GCVE-VVD-MAGEIA-2017-308
Advisory Published
Transit path validation inadvertently caused the previous hop realm to
not be added to the transit path of issued tickets. This may, in some
cases, enable bypass of capath policy in Heimdal versions 1.5 through
7.2 (CVE-2017-6594).
Note, this may break sites that rely on the bug. With the bug some
incomplete [capaths] worked, that should not have. These may now break
authentication in some cross-realm configurations.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | heimdal | 0 (affected), 1.5.3-6.2.mga5 (unaffected) | — |
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.