CVE-2022-3116: Null Pointer Dereference
Last updated 24 July 2024
Other sources
The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-3116?
CVE-2022-3116 is a vulnerability in the Heimdal Software Kerberos 5 implementation that allows an attacker with network access to crash an application that depends on the vulnerable code path.
How can an attacker exploit CVE-2022-3116?
An attacker with network access to an application that depends on the vulnerable code path can exploit CVE-2022-3116 to cause the application to crash.
Which software versions are affected by CVE-2022-3116?
The Heimdal Software versions 7.5.0+dfsg-1ubuntu0.1, 7.7.0+dfsg-1ubuntu1.1, 1.6~, and 1.7~ are affected by CVE-2022-3116.
How can I fix CVE-2022-3116 on Ubuntu?
To fix CVE-2022-3116 on Ubuntu, you need to update the Heimdal package to version 7.5.0+dfsg-1ubuntu0.1 (for bionic) or 7.7.0+dfsg-1ubuntu1.1 (for focal).
How can I fix CVE-2022-3116 on Debian?
To fix CVE-2022-3116 on Debian, you need to update the Heimdal package to a version that includes the fixes for this vulnerability.