CVE-2019-12098: High severity Heimdal Project Heimdal vulnerability
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5initcredsstep in lib/krb5/initcredspw.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12098?
CVE-2019-12098 is a vulnerability in the client side of Heimdal before 7.6.0 that allows for a man-in-the-middle attack by not verifying anonymous PKINIT PA-PKINIT-KX key exchange.
Which software versions are affected by CVE-2019-12098?
The affected software versions include Heimdal 7.5.0+dfsg-1ubuntu0.1, Heimdal 1.6~ on Ubuntu Trusty, Heimdal 7.6 on Ubuntu (upstream), and Heimdal 1.7~ on Ubuntu Xenial.
What is the severity of CVE-2019-12098?
CVE-2019-12098 has a severity rating of high (7 out of 10).
How can I fix CVE-2019-12098?
To fix CVE-2019-12098, update Heimdal to version 7.6.0 or later.
Where can I find more information about CVE-2019-12098?
You can find more information about CVE-2019-12098 on the MITRE CVE database, Heimdal mailing list, and GitHub.