Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 878425

Summary: app-crypt/heimdal: Buffer overflow in DES/DES3
Product: Gentoo Security Reporter: Sam James <sam>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: kerberos
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [ebuild]
Package list:
Runtime testing required: ---

Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-10-27 05:16:51 UTC
See https://github.com/heimdal/heimdal/pull/1018.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-10-27 05:17:16 UTC
"o CVE-2022-3437:  There is a limited write heap buffer overflow in the GSSAPI
                  unwrap_des() and unwrap_des3() routines of Heimdal (included
                  in Samba).
https://www.samba.org/samba/security/CVE-2022-3437.html
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-16 15:14:51 UTC

*** This bug has been marked as a duplicate of bug 881429 ***