Unrated severityNVD Advisory· Published Nov 15, 2022· Updated Apr 23, 2025
Read one byte past a buffer when normalizing Unicode
CVE-2022-41916
Description
Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/libheimdal&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/libheimdal&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/libheimdal&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/libheimdal&distro=SUSE%20Package%20Hub%2015%20SP4
< 7.8.0-bp153.2.4.1+ 3 more
- (no CPE)range: < 7.8.0-bp153.2.4.1
- (no CPE)range: < 7.8.0-bp154.2.4.1
- (no CPE)range: < 7.8.0-bp153.2.4.1
- (no CPE)range: < 7.8.0-bp154.2.4.1
Patches
Vulnerability mechanics
References
5- security.gentoo.org/glsa/202310-06mitrevendor-advisory
- www.debian.org/security/2022/dsa-5287mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2022/11/msg00034.htmlmitremailing-list
- github.com/heimdal/heimdal/security/advisories/GHSA-mgqr-gvh6-23cxmitre
- security.netapp.com/advisory/ntap-20230216-0008/mitre
News mentions
0No linked articles in our index yet.