CVE-2017-11103: Apple iPhone OS

High severity, CVSS 8.1. EPSS: 5.1% chance of exploitation in the next 30 days.

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.

Affected products

  • Apple iPhone OS: before 11.0 (fixed in 11.0)
  • Apple Mac OS X: before 10.13.1 (fixed in 10.13.1)
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Freebsd Freebsd: affected versions not specified
  • Heimdal Project Heimdal: before 7.4.0 (fixed in 7.4.0)
  • Samba Samba: from 4.0.0, before 4.4.15 (fixed in 4.4.15); from 4.5.0, before 4.5.12 (fixed in 4.5.12); from 4.6.0, before 4.6.6 (fixed in 4.6.6)

Published 2017-07-13. Last modified 2026-06-17.