Vulnerability Details CVE-2017-17439
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_string function in lib/asn1/der_length.c.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.091
EPSS Ranking 92.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-17439
-
cpe:2.3:a:heimdal_project:heimdal:0.0j
-
cpe:2.3:a:heimdal_project:heimdal:0.0k
-
cpe:2.3:a:heimdal_project:heimdal:0.0l
-
cpe:2.3:a:heimdal_project:heimdal:0.0m
-
cpe:2.3:a:heimdal_project:heimdal:0.0n
-
cpe:2.3:a:heimdal_project:heimdal:0.0o
-
cpe:2.3:a:heimdal_project:heimdal:0.0p
-
cpe:2.3:a:heimdal_project:heimdal:0.0q
-
cpe:2.3:a:heimdal_project:heimdal:0.0r
-
cpe:2.3:a:heimdal_project:heimdal:0.0s
-
cpe:2.3:a:heimdal_project:heimdal:0.0t
-
cpe:2.3:a:heimdal_project:heimdal:0.0u
-
cpe:2.3:a:heimdal_project:heimdal:0.1a
-
cpe:2.3:a:heimdal_project:heimdal:0.1b
-
cpe:2.3:a:heimdal_project:heimdal:0.1c
-
cpe:2.3:a:heimdal_project:heimdal:0.1d
-
cpe:2.3:a:heimdal_project:heimdal:0.1e
-
cpe:2.3:a:heimdal_project:heimdal:0.1f
-
cpe:2.3:a:heimdal_project:heimdal:0.1g
-
cpe:2.3:a:heimdal_project:heimdal:0.1h
-
cpe:2.3:a:heimdal_project:heimdal:0.1i
-
cpe:2.3:a:heimdal_project:heimdal:0.1j
-
cpe:2.3:a:heimdal_project:heimdal:0.1k
-
cpe:2.3:a:heimdal_project:heimdal:0.1l
-
cpe:2.3:a:heimdal_project:heimdal:0.1m
-
cpe:2.3:a:heimdal_project:heimdal:0.2a
-
cpe:2.3:a:heimdal_project:heimdal:0.2b
-
cpe:2.3:a:heimdal_project:heimdal:0.2c
-
cpe:2.3:a:heimdal_project:heimdal:0.2d
-
cpe:2.3:a:heimdal_project:heimdal:0.2e
-
cpe:2.3:a:heimdal_project:heimdal:0.2f
-
cpe:2.3:a:heimdal_project:heimdal:0.2g
-
cpe:2.3:a:heimdal_project:heimdal:0.2h
-
cpe:2.3:a:heimdal_project:heimdal:0.2i
-
cpe:2.3:a:heimdal_project:heimdal:0.2j
-
cpe:2.3:a:heimdal_project:heimdal:0.2k
-
cpe:2.3:a:heimdal_project:heimdal:0.2l
-
cpe:2.3:a:heimdal_project:heimdal:0.2m
-
cpe:2.3:a:heimdal_project:heimdal:0.2n
-
cpe:2.3:a:heimdal_project:heimdal:0.2o
-
cpe:2.3:a:heimdal_project:heimdal:0.2p
-
cpe:2.3:a:heimdal_project:heimdal:0.2q
-
cpe:2.3:a:heimdal_project:heimdal:0.2r
-
cpe:2.3:a:heimdal_project:heimdal:0.2s
-
cpe:2.3:a:heimdal_project:heimdal:0.2t
-
cpe:2.3:a:heimdal_project:heimdal:0.3a
-
cpe:2.3:a:heimdal_project:heimdal:0.3b
-
cpe:2.3:a:heimdal_project:heimdal:0.3c
-
cpe:2.3:a:heimdal_project:heimdal:0.3d
-
cpe:2.3:a:heimdal_project:heimdal:0.3e
-
cpe:2.3:a:heimdal_project:heimdal:0.3f
-
cpe:2.3:a:heimdal_project:heimdal:0.4.d
-
cpe:2.3:a:heimdal_project:heimdal:0.4.e
-
cpe:2.3:a:heimdal_project:heimdal:0.4.f
-
cpe:2.3:a:heimdal_project:heimdal:0.4a
-
cpe:2.3:a:heimdal_project:heimdal:0.4b
-
cpe:2.3:a:heimdal_project:heimdal:0.4c
-
cpe:2.3:a:heimdal_project:heimdal:0.5
-
cpe:2.3:a:heimdal_project:heimdal:0.5.1
-
cpe:2.3:a:heimdal_project:heimdal:0.5.2
-
cpe:2.3:a:heimdal_project:heimdal:0.5.3
-
cpe:2.3:a:heimdal_project:heimdal:0.6
-
cpe:2.3:a:heimdal_project:heimdal:0.6.1
-
cpe:2.3:a:heimdal_project:heimdal:0.6.2
-
cpe:2.3:a:heimdal_project:heimdal:0.6.3
-
cpe:2.3:a:heimdal_project:heimdal:0.6.4
-
cpe:2.3:a:heimdal_project:heimdal:0.6.5
-
cpe:2.3:a:heimdal_project:heimdal:0.6.6
-
cpe:2.3:a:heimdal_project:heimdal:0.7
-
cpe:2.3:a:heimdal_project:heimdal:0.7.1
-
cpe:2.3:a:heimdal_project:heimdal:0.7.2
-
cpe:2.3:a:heimdal_project:heimdal:0.8
-
cpe:2.3:a:heimdal_project:heimdal:0.8.1
-
cpe:2.3:a:heimdal_project:heimdal:0.9
-
cpe:2.3:a:heimdal_project:heimdal:1.0.0
-
cpe:2.3:a:heimdal_project:heimdal:1.0.1
-
cpe:2.3:a:heimdal_project:heimdal:1.0.2
-
cpe:2.3:a:heimdal_project:heimdal:1.1.0
-
cpe:2.3:a:heimdal_project:heimdal:1.2.0
-
cpe:2.3:a:heimdal_project:heimdal:1.2.1
-
cpe:2.3:a:heimdal_project:heimdal:1.3.0
-
cpe:2.3:a:heimdal_project:heimdal:1.3.1
-
cpe:2.3:a:heimdal_project:heimdal:1.3.2
-
cpe:2.3:a:heimdal_project:heimdal:1.3.3
-
cpe:2.3:a:heimdal_project:heimdal:1.4.0
-
cpe:2.3:a:heimdal_project:heimdal:1.4.1
-
cpe:2.3:a:heimdal_project:heimdal:1.5.0
-
cpe:2.3:a:heimdal_project:heimdal:1.5.1
-
cpe:2.3:a:heimdal_project:heimdal:1.5.2
-
cpe:2.3:a:heimdal_project:heimdal:1.5.3
-
cpe:2.3:a:heimdal_project:heimdal:1.6.0
-
cpe:2.3:a:heimdal_project:heimdal:7.0.1
-
cpe:2.3:a:heimdal_project:heimdal:7.0.2
-
cpe:2.3:a:heimdal_project:heimdal:7.0.3
-
cpe:2.3:a:heimdal_project:heimdal:7.1.0
-
cpe:2.3:a:heimdal_project:heimdal:7.2.0
-
cpe:2.3:a:heimdal_project:heimdal:7.3.0
-
cpe:2.3:a:heimdal_project:heimdal:7.4.0
-
cpe:2.3:o:debian:debian_linux:9.0