Skip to content

NULL dereference DoS in SPNEGO acceptors

Low
nicowilliams published GHSA-69h9-669w-88xv Nov 15, 2022

Package

heimdal

Affected versions

<7.7.1

Patched versions

7.7.1, 7.8

Description

Impact

This is a denial of service vulnerability affecting server applications that use SPNEGO.

Patches

Users should upgrade to Heimdal 7.7.1 or Heimdal 7.8.

Workarounds

Disable SPNEGO in the application.

For more information

If you have any questions or comments about this advisory:

Severity

Low
0.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

CVE ID

CVE-2021-44758

Weaknesses

No CWEs