In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-05-15T22:41:11

Updated: 2024-08-04T23:10:30.560Z

Reserved: 2019-05-14T00:00:00

Link: CVE-2019-12098

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-15T23:29:00.277

Modified: 2023-11-07T03:03:28.500

Link: CVE-2019-12098

cve-icon Redhat

No data.