CVE-2017-6594: High severity Heimdal Project Heimdal vulnerability
Published Aug 28, 2017
·Updated
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.
Affected Software
3 affected components
Heimdal Project Heimdal<=7.2.0
openSUSE Leap=42.2
openSUSE Leap=42.3
Remediation
Event History
Aug 28, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-6594?
CVE-2017-6594 is considered a medium severity vulnerability.
2
How do I fix CVE-2017-6594?
To fix CVE-2017-6594, upgrade the Heimdal software to version 7.3 or later.
3
Which software is affected by CVE-2017-6594?
CVE-2017-6594 affects Heimdal prior to version 7.3, as well as specific versions of openSUSE Leap 42.2 and 42.3.
4
What type of vulnerability is CVE-2017-6594?
CVE-2017-6594 is a vulnerability related to transit path validation in the Heimdal authentication protocols.
5
Can CVE-2017-6594 be exploited remotely?
Yes, CVE-2017-6594 can potentially be exploited by attackers remotely if the conditions are met.