Vulnerability Description
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Heimdal Project | Heimdal | < 7.7.1 |
Related Weaknesses (CWE)
References
- https://github.com/heimdal/heimdal/commit/f9ec7002cdd526ae84fbacbf153162e118f225PatchThird Party Advisory
- https://github.com/heimdal/heimdal/security/advisories/GHSA-69h9-669w-88xvThird Party Advisory
- https://security.gentoo.org/glsa/202310-06
- https://github.com/heimdal/heimdal/commit/f9ec7002cdd526ae84fbacbf153162e118f225PatchThird Party Advisory
- https://github.com/heimdal/heimdal/security/advisories/GHSA-69h9-669w-88xvThird Party Advisory
- https://security.gentoo.org/glsa/202310-06
FAQ
What is CVE-2021-44758?
CVE-2021-44758 is a vulnerability with a CVSS score of 7.5 (HIGH). Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.
How severe is CVE-2021-44758?
CVE-2021-44758 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44758?
Check the references section above for vendor advisories and patch information. Affected products include: Heimdal Project Heimdal.