CVE-2022-45142: accidental logic inversion in signature verification in gsskrb5

Related Vulnerabilities: CVE-2022-45142  

Debian Bug report logs - #1030849
CVE-2022-45142: accidental logic inversion in signature verification in gsskrb5

version graph

Package: src:heimdal; Maintainer for src:heimdal is Brian May <bam@debian.org>;

Reported by: Helmut Grohne <helmut@subdivi.de>

Date: Wed, 8 Feb 2023 11:45:14 UTC

Severity: grave

Tags: upstream

Found in version heimdal/7.8.git20221117.28daf24+dfsg-1

Forwarded to https://www.openwall.com/lists/oss-security/2023/02/08/1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Brian May <bam@debian.org>:
Bug#1030849; Package src:heimdal. (Wed, 08 Feb 2023 11:45:16 GMT) (full text, mbox, link).


Acknowledgement sent to Helmut Grohne <helmut@subdivi.de>:
New Bug report received and forwarded. Copy sent to Brian May <bam@debian.org>. (Wed, 08 Feb 2023 11:45:16 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Helmut Grohne <helmut@subdivi.de>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2022-45142: accidental logic inversion in signature verification in gsskrb5
Date: Wed, 8 Feb 2023 12:43:02 +0100
Source: heimdal
Version: 7.8.git20221117.28daf24+dfsg-1
Severity: grave
Tags: upstream
Forwarded: https://www.openwall.com/lists/oss-security/2023/02/08/1

Hi,

Debian's heimdal is also vulnerable to CVE-2022-45142. Refer to the
openwall publication for details. Note that this vulnerability only
applies to heimdal's maintenance branches and never affected its main
development branch. It can be fixed either by applying the patch or by
moving to the development branch.

Salvatore will be issuing a DSA today. I'll be taking care of older
releases.

Helmut




Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Feb 8 13:06:25 2023; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.