{"id":"MGASA-2023-0098","summary":"Updated heimdal packages fix security vulnerability","details":"The fix for CVE-2022-3437 included changing memcmp to be constant time and\na workaround for a compiler bug by adding \"!= 0\" comparisons to the result\nof memcmp. When these patches were backported a logic inversion sneaked in\ncausing the validation of message integrity codes in gssapi/arcfour to be\ninverted. (CVE-2022-45142)\n","modified":"2026-04-16T04:42:25.955205513Z","published":"2023-03-18T22:16:28Z","upstream":["CVE-2022-45142"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0098.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31530"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/02/08/1"},{"type":"WEB","url":"https://www.debian.org/security/2023/dsa-5344"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5849-1"}],"affected":[{"package":{"name":"heimdal","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/heimdal?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.7.1-1.3.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0098.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}