heimdal-7.7.1-3.fc35

Read Time:41 Second

FEDORA-2022-cbbd105d08

Packages in this update:

heimdal-7.7.1-3.fc35

Update description:

Fixes:

Delay service starts until after network is online (rhbz#2005501)
Restart services on package update (will apply when updating from this release)

This release fixes the following Security Vulnerabilities:

CVE-2022-42898 PAC parse integer overflows
CVE-2022-3437 Overflows and non-constant time leaks in DES{,3} and arcfour
CVE-2022-41916 Fix Unicode normalization read of 1 bytes past end of array
CVE-2021-44758 NULL dereference DoS in SPNEGO acceptors
CVE-2021-3671 A null pointer de-reference when handling missing sname in TGS-REQ
CVE-2022-44640 Heimdal KDC: invalid free in ASN.1 codec

Note that CVE-2022-44640 is a severe vulnerability, possibly a 10.0 on the Common Vulnerability Scoring System (CVSS) v3.

Read More