news 28 Posted July 14, 2017 Package : heimdal Version : 1.6~git20120403+dfsg1-2+deb7u1 CVE ID : CVE-2017-11103 Debian Bug : 868208 Jeffrey Altman, Viktor Duchovni and Nico Williams identified a mutual authentication bypass vulnerability in Heimdal Kerberos. Also known as Orpheus' Lyre, this vulnerability could be used by an attacker to mount a service impersonation attack on the client if he's on the network path between the client and the service. More details can be found on the vulnerability website (https://orpheus-lyre.info/). For Debian 7 "Wheezy", these problems have been fixed in version 1.6~git20120403+dfsg1-2+deb7u1. We recommend that you upgrade your heimdal packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Share this post Link to post