Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-12098
Description:In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Test IDs: 1.3.6.1.4.1.25623.1.0.704455   1.3.6.1.4.1.25623.1.0.877108   1.3.6.1.4.1.25623.1.0.877324  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-12098
Bugtraq: 20190603 [SECURITY] [DSA 4455-1] heimdal security update (Google Search)
https://seclists.org/bugtraq/2019/Jun/1
Debian Security Information: DSA-4455 (Google Search)
https://www.debian.org/security/2019/dsa-4455
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SLXXIF4LOQEAEDAF4UGP2AO6WDNTDFUB/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIXEDVVMPD6ZAJSMI2EZ7FNEIVNWE5PD/
https://github.com/heimdal/heimdal/compare/3e58559...bbafe72
https://github.com/heimdal/heimdal/releases/tag/heimdal-7.6.0
SuSE Security Announcement: openSUSE-SU-2019:1682 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00002.html
SuSE Security Announcement: openSUSE-SU-2019:1688 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00003.html
SuSE Security Announcement: openSUSE-SU-2019:1888 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html




© 1998-2025 E-Soft Inc. All rights reserved.