GCVE-VVD-MAGEIA-2017-308
Advisory Published
Vulnetix · Advisory published August 25, 2017
Transit path validation inadvertently caused the previous hop realm to
not be added to the transit path of issued tickets. This may, in some
cases, enable bypass of capath policy in Heimdal versions 1.5 through
7.2 (CVE-2017-6594).
Note, this may break sites that rely on the bug. With the bug some
incomplete [capaths] worked, that should not have. These may now break
authentication in some cross-realm configurations.