Jump to content
Compatible Support Forums
Sign in to follow this  
news

[SECURITY] [DLA 1027-1] heimdal security update

Recommended Posts

Package : heimdal

Version : 1.6~git20120403+dfsg1-2+deb7u1

CVE ID : CVE-2017-11103

Debian Bug : 868208

 

Jeffrey Altman, Viktor Duchovni and Nico Williams identified a mutual

authentication bypass vulnerability in Heimdal Kerberos. Also known as

Orpheus' Lyre, this vulnerability could be used by an attacker to mount

a service impersonation attack on the client if he's on the network

path between the client and the service.

 

More details can be found on the vulnerability website

(https://orpheus-lyre.info/).

 

For Debian 7 "Wheezy", these problems have been fixed in version

1.6~git20120403+dfsg1-2+deb7u1.

 

We recommend that you upgrade your heimdal packages.

 

Further information about Debian LTS security advisories, how to apply

these updates to your system and frequently asked questions can be

found at: https://wiki.debian.org/LTS

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×