CVE-2017-11103
Description
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 7.4.0.dfsg.1-1 |
| debian | bullseye | fixed | 7.4.0.dfsg.1-1 |
| debian | forky | fixed | 7.4.0.dfsg.1-1 |
| debian | sid | fixed | 7.4.0.dfsg.1-1 |
| debian | trixie | fixed | 7.4.0.dfsg.1-1 |
| debian | 8.0 | affected | |
| debian | 9.0 | affected | |
| debian | 10.0 | affected | |
| macos | affected | 11.0 | |
| freebsd | - | affected | |
References
- http://www.debian.org/security/2017/dsa-3912
- http://www.h5l.org/advisories.html?show=2017-07-11
- http://www.securityfocus.com/bid/99551
- http://www.securitytracker.com/id/1038876
- http://www.securitytracker.com/id/1039427
- https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0
- https://support.apple.com/HT208112
- https://support.apple.com/HT208144
- https://support.apple.com/HT208221
- https://www.freebsd.org/security/advisories/FreeBSD-SA-17:05.heimdal.asc
- https://www.orpheus-lyre.info/
- https://www.samba.org/samba/security/CVE-2017-11103.html
- https://security-tracker.debian.org/tracker/CVE-2017-11103
CWEs
CWE-345
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.