CVE-2021-44758: Null Pointer Dereference
Published Dec 26, 2022
·Updated
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferredmechtype of GSSCNOOID and a nonzero initialresponse value to sendaccept.
Affected Software
2 affected componentsFixes available
debian/heimdal<=7.5.0+dfsg-3
7.5.0+dfsg-3+deb10u27.7.0+dfsg-2+deb11u37.8.git20221117.28daf24+dfsg-27.8.git20221117.28daf24+dfsg-3
Heimdal Project Heimdal<7.7.1
Remediation
Event History
Dec 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-44758?
CVE-2021-44758 is a vulnerability in Heimdal before version 7.7.1 that allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor.
2
How severe is CVE-2021-44758?
CVE-2021-44758 is considered high severity with a CVSS score of 7.5.
3
How can attackers exploit CVE-2021-44758?
Attackers can exploit CVE-2021-44758 by sending a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to the SPNEGO acceptor.
4
Which software versions are affected by CVE-2021-44758?
Heimdal versions before 7.7.1 are affected by CVE-2021-44758.
5
How can I fix CVE-2021-44758?
To fix CVE-2021-44758, upgrade to Heimdal version 7.7.1 or later.