Helmut Grohne discovered a flaw in Heimdal, an implementation of
Kerberos 5 that aims to be compatible with MIT Kerberos. The backports
of fixes for CVE-2022-3437 accidentally inverted important memory
comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check
handlers for gssapi, resulting in incorrect validation of message
integrity codes.
More Stories
c-ares-1.34.5-1.fc40
FEDORA-2025-942a0d7e5d Packages in this update: c-ares-1.34.5-1.fc40 Update description: Update to 1.34.5. Fixes CVE-2025-31498. Read More
c-ares-1.34.5-1.fc42
FEDORA-2025-19b0cab086 Packages in this update: c-ares-1.34.5-1.fc42 Update description: Update to 1.34.5. Fixes CVE-2025-31498. Read More
c-ares-1.34.5-1.fc41
FEDORA-2025-c26ac54608 Packages in this update: c-ares-1.34.5-1.fc41 Update description: Update to 1.34.5. Fixes CVE-2025-31498. Read More
A Vulnerability in Google Chrome Could Allow for Arbitrary Code Execution
A vulnerability has been discovered in Google Chrome, which could allow for arbitrary code execution. Successful exploitation of this vulnerability...
Multiple Vulnerabilities in Ivanti Endpoint Manager Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered in Ivanti Endpoint Manager, the most severe of which could allow for remote code execution....
Critical Patches Issued for Microsoft Products, April 8, 2025
Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution in...