alpine · CVE-2019-12098

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2019-12098: 1 source package rows (heimdal); 16 state rows across 6 repos (3.10-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 1, open 15.

Description:

In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.

cvelogic Threat Intelligence