Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-11103
HistoryJul 13, 2017 - 12:00 a.m.

CVE-2017-11103

2017-07-1300:00:00
ubuntu.com
ubuntu.com
15

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.047

Percentile

92.7%

Heimdal before 7.4 allows remote attackers to impersonate services with
Orpheus’ Lyre attacks because it obtains service-principal names in a way
that violates the Kerberos 5 protocol specification. In
_krb5_extract_ticket() the KDC-REP service name must be obtained from the
encrypted version stored in β€˜enc_part’ instead of the unencrypted version
stored in β€˜ticket’. Use of the unencrypted version provides an opportunity
for successful server impersonation and other attacks. NOTE: this CVE is
only for Heimdal and other products that embed Heimdal code; it does not
apply to other instances in which this part of the Kerberos 5 protocol
specification is violated.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchheimdal<Β 1.6~git20131207+dfsg-1ubuntu1.2UNKNOWN
ubuntu16.04noarchheimdal<Β 1.7~git20150920+dfsg-4ubuntu1.16.04.1UNKNOWN
ubuntu16.10noarchheimdal<Β 1.7~git20150920+dfsg-4ubuntu1.16.10.1UNKNOWN
ubuntu17.04noarchheimdal<Β 7.1.0+dfsg-9ubuntu1.1UNKNOWN
ubuntu14.04noarchsamba<Β 2:4.3.11+dfsg-0ubuntu0.14.04.10UNKNOWN
ubuntu16.04noarchsamba<Β 2:4.3.11+dfsg-0ubuntu0.16.04.9UNKNOWN
ubuntu16.10noarchsamba<Β 2:4.4.5+dfsg-2ubuntu5.8UNKNOWN
ubuntu17.04noarchsamba<Β 2:4.5.8+dfsg-0ubuntu0.17.04.4UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.047

Percentile

92.7%