CVE Vulnerabilities

CVE-2012-5484

Published: Jan 27, 2013 | Modified: Feb 07, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.9 HIGH
AV:A/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:A/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

Affected Software

Name Vendor Start Version End Version
Freeipa Redhat 2.0.0 (including) 2.0.0 (including)
Freeipa Redhat 2.0.1 (including) 2.0.1 (including)
Freeipa Redhat 2.1.0 (including) 2.1.0 (including)
Freeipa Redhat 2.1.1 (including) 2.1.1 (including)
Freeipa Redhat 2.1.3 (including) 2.1.3 (including)
Freeipa Redhat 2.1.4 (including) 2.1.4 (including)
Freeipa Redhat 2.2.1 (including) 2.2.1 (including)
Red Hat Enterprise Linux 5 RedHat ipa-client-0:2.1.3-5.el5_9.2 *
Red Hat Enterprise Linux 6 RedHat ipa-0:2.2.0-17.el6_3.1 *
Freeipa Ubuntu precise *
Freeipa Ubuntu quantal *
Freeipa Ubuntu upstream *

References