{"schema_version":"1.7.5","id":"CVE-2017-11103","published":"2017-07-13T13:29:00.173Z","modified":"2026-07-08T05:50:15.881863768Z","related":["SUSE-SU-2017:2237-1","openSUSE-SU-2024:10946-1","openSUSE-SU-2024:11365-1"],"details":"Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/heimdal/heimdal","events":[{"introduced":"0"},{"fixed":"a3d72c604378e0bff787cc426f2b17f75b112dce"}],"database_specific":{"cpe":"cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.4.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["heimdal-1.3.0pre1","heimdal-7.3.0","heimdal-7.2.0","heimdal-7.1.0","heimdal-7.0.3","heimdal-7.0.2","heimdal-7.0.1","heimdal-7.1rc1","git2svn-syncpoint-master","heimdal-1.5pre2","heimdal-1.5pre1","upstream-1.4.0+git20110220.dfsg.1","upstream-1.4.0+git20101228.dfsg.1","heimdal-1.3.0rc1","heimdal-1.3.0pre11","heimdal-1.3.0pre10","heimdal-1.3.0pre9","heimdal-1.3.0pre8","heimdal-1.3.0pre7","heimdal-1.3.0pre6","heimdal-1.3.0pre5","heimdal-1.3.0pre4","heimdal-1.3.0pre3","switch-from-svn-to-git"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11103.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/samba-team/samba","events":[{"introduced":"df33344d8eb40221d60c99931690703a11d91bc2"},{"fixed":"9fb0aa56baf317c5bf18417c5516f951207af82d"},{"introduced":"916fab083a8cb5c10365da7f3a85d0bbfde4a30e"},{"fixed":"6e6361ee4fd28098638850e3eda3d4ac2c3396f4"},{"introduced":"f17816a4ae2bb0ed45561347a4c578ca9ab28ccf"},{"fixed":"55d71509595075a17eb2baf0d89c4801ba2f03f3"}],"database_specific":{"cpe":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.4.15"},{"introduced":"4.5.0"},{"fixed":"4.5.12"},{"introduced":"4.6.0"},{"fixed":"4.6.6"}],"source":"CPE_RANGE"}}],"versions":["samba-4.5.11","samba-4.6.5","samba-4.6.3","samba-4.5.9","samba-4.6.0","samba-4.5.6","samba-4.5.5","samba-4.5.4","samba-4.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11103.json"}}],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3912"},{"type":"ADVISORY","url":"http://www.h5l.org/advisories.html?show=2017-07-11"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99551"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1038876"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039427"},{"type":"ADVISORY","url":"https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0"},{"type":"ADVISORY","url":"https://support.apple.com/HT208112"},{"type":"ADVISORY","url":"https://support.apple.com/HT208144"},{"type":"ADVISORY","url":"https://support.apple.com/HT208221"},{"type":"ADVISORY","url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-17:05.heimdal.asc"},{"type":"ADVISORY","url":"https://www.orpheus-lyre.info/"},{"type":"ADVISORY","url":"https://www.samba.org/samba/security/CVE-2017-11103.html"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"11.0"}],"source":"CPE_RANGE","vendor_product":"apple:iphone_os"},{"cpes":["cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"10.13.1"}],"source":"CPE_RANGE","vendor_product":"apple:mac_os_x"},{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}