CVE-2022-45142
HIGHHeimdal - Improper Validation of Integrity Check Value in GSSAPI ArcFour
Title source: llmDescription
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
References (2)
Core 2
Core References
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202310-06
Scores
CVSS v3
7.5
EPSS
0.0049
EPSS Percentile
37.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-354
Status
published
Products (2)
heimdal_project/heimdal
7.7.1
heimdal_project/heimdal
7.8.0
Published
Mar 06, 2023
Tracked Since
Feb 18, 2026