First published: Mon Dec 26 2022(Updated: )
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Heimdal Project Heimdal | <7.7.1 | |
debian/heimdal | <=7.5.0+dfsg-3 | 7.5.0+dfsg-3+deb10u2 7.7.0+dfsg-2+deb11u3 7.8.git20221117.28daf24+dfsg-2 7.8.git20221117.28daf24+dfsg-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44758 is a vulnerability in Heimdal before version 7.7.1 that allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor.
CVE-2021-44758 is considered high severity with a CVSS score of 7.5.
Attackers can exploit CVE-2021-44758 by sending a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to the SPNEGO acceptor.
Heimdal versions before 7.7.1 are affected by CVE-2021-44758.
To fix CVE-2021-44758, upgrade to Heimdal version 7.7.1 or later.