Oval Definition:oval:com.ubuntu.xenial:def:2017111030000000
Revision Date:2017-07-13Version:1
Title:CVE-2017-11103 on Ubuntu 16.04 LTS (xenial) - medium.
Description:Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-11103
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • heimdal package in xenial was vulnerable but has been fixed (note: '1.7~git20150920+dfsg-4ubuntu1.16.04.1').
  • OR samba package in xenial was vulnerable but has been fixed (note: '2:4.3.11+dfsg-0ubuntu0.16.04.9').
  • BACK