Bug 22142 - heimdal new security issue CVE-2017-17439
Summary: heimdal new security issue CVE-2017-17439
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: https://www.debian.org/security/2017/...
Whiteboard: MGA6-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2017-12-08 09:39 CET by Zombie Ryushu
Modified: 2017-12-31 16:15 CET (History)
4 users (show)

See Also:
Source RPM: heimdal-7.4.0-2.mga7.src.rpm
CVE: CVE-2017-17439
Status comment:


Attachments

Description Zombie Ryushu 2017-12-08 09:39:40 CET
New security flaw in Heimdal:

https://www.debian.org/security/2017/dsa-4056
Zombie Ryushu 2017-12-08 09:39:56 CET

CVE: (none) => CVE-2017-16239

Comment 1 Marja Van Waes 2017-12-08 15:54:47 CET
Assigning to the registered heimdal maintainer.

I think the link and CVE are wrong, though, so changing them where I can, because of:

Debian Security Advisory DSA-4055-1                   security@debian.org
https://www.debian.org/security/                       Sebastien Delafond
December 07, 2017                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : heimdal
CVE ID         : CVE-2017-17439
Debian Bug     : 878144


___________________________________________________________________________


I don't know whether it needs to be fixed in Mageia 5, too

CC: (none) => marja11
Whiteboard: (none) => MGA6TOO
Assignee: bugsquad => guillomovitch
CVE: CVE-2017-16239 => CVE-2017-17439
Version: 6 => Cauldron
URL: https://www.debian.org/security/2017/dsa-4056 => https://www.debian.org/security/2017/dsa-4055
Summary: heimdal security vulnerability CVE-2017-16239 => heimdal security vulnerability CVE-2017-17439

Comment 2 David Walser 2017-12-08 18:38:42 CET
Indeed, the correct DSA link from December 7:
https://www.debian.org/security/2017/dsa-4055

Source RPM: heimdal => heimdal-7.4.0-2.mga7.src.rpm
Summary: heimdal security vulnerability CVE-2017-17439 => heimdal new security issue CVE-2017-17439

Comment 3 Guillaume Rousse 2017-12-16 12:20:16 CET
Fixed package submitted in updates_testing for mageia 6.
Comment 4 David Walser 2017-12-16 18:59:57 CET
Advisory:
========================

Updated heimdal packages fix security vulnerability:

Michael Eder and Thomas Kittel discovered that Heimdal did not correctly handle
ASN.1 data. This would allow an unauthenticated remote attacker to cause a
denial of service (crash of the KDC daemon) by sending maliciously crafted
packets (CVE-2017-17439).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17439
https://www.debian.org/security/2017/dsa-4055
========================

Updated packages in core/updates_testing:
========================
heimdal-workstation-7.3.0-1.2.mga6
heimdal-server-7.3.0-1.2.mga6
heimdal-libs-7.3.0-1.2.mga6
heimdal-devel-7.3.0-1.2.mga6
heimdal-devel-doc-7.3.0-1.2.mga6

from heimdal-7.3.0-1.2.mga6.src.rpm

CC: (none) => guillomovitch
Whiteboard: MGA6TOO => (none)
Version: Cauldron => 6
Assignee: guillomovitch => qa-bugs

Comment 5 Herman Viaene 2017-12-28 14:57:38 CET
MGA6-32 on Dell Latitude D600 MATE
No installation issues
Based on tests in bug 21550 Comment 4
# systemctl start heimdal
Failed to start heimdal.service: Unit heimdal.service not found.
After some googling found that things have changed it seems
# systemctl start heimdal-kdc
# systemctl -l status heimdal-kdc
● heimdal-kdc.service - Heimdal KDC is a Kerberos 5 Key Distribution Center server
   Loaded: loaded (/usr/lib/systemd/system/heimdal-kdc.service; enabled; vendor preset: enabled)
   Active: active (running) since do 2017-12-28 14:48:53 CET; 24s ago
     Docs: man:kdc(8)
           info:heimdal
           http://www.h5l.org/
 Main PID: 18121 (kdc)
   CGroup: /system.slice/heimdal-kdc.service
           ├─18121 /usr/libexec/kdc
           └─18124 /usr/libexec/kdc

dec 28 14:48:53 mach6.hviaene.thuis systemd[1]: Started Heimdal KDC is a Kerberos 5 Key Distribution Cent
and
# kadmin 
kadmin: kadm5_init_with_password: No KDC found for realm HVIAENE.THUIS
That is correct
As normal user:$ verify_krb5_conf 
verify_krb5_conf: krb5_config_parse_file: open /home/tester6/.krb5/config: No such file or directory
verify_krb5_conf: /libdefaults/rdns: unknown entry
verify_krb5_conf: /libdefaults/default_ccache_name: unknown entry
I can accept that.

Whiteboard: (none) => MGA6-32-OK
CC: (none) => herman.viaene

Comment 6 Lewis Smith 2017-12-31 15:29:20 CET
Thanks yet again for a sticky test. Advisoried, validating.

Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 7 Mageia Robot 2017-12-31 16:15:43 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2017-0485.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.