CVE-2022-45142 is a logic inversion vulnerability affecting the heimdal_project heimdal library, specifically within the gssapi/arcfour message integrity code validation. This flaw, introduced during the backporting of a fix for a previous CVE, causes the integrity checks to be inverted. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low complexity, potentially leading to high integrity impact without requiring user interaction. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.7.1CPE matchmatch criteria | cpe:2.3:a:heimdal_project:heimdal:7.7.1:*:*:*:*:*:*:* | ||
7.8.0CPE matchmatch criteria | cpe:2.3:a:heimdal_project:heimdal:7.8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
Mar 14, 2023samba: fix introduced a logic inversion
Feb 8, 2023