CVE Vulnerabilities

CVE-2012-5484

Published: Jan 27, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.9 HIGH
AV:A/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:A/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

Affected Software

NameVendorStart VersionEnd Version
FreeipaRedhat2.0.0 (including)2.0.0 (including)
FreeipaRedhat2.0.1 (including)2.0.1 (including)
FreeipaRedhat2.1.0 (including)2.1.0 (including)
FreeipaRedhat2.1.1 (including)2.1.1 (including)
FreeipaRedhat2.1.3 (including)2.1.3 (including)
FreeipaRedhat2.1.4 (including)2.1.4 (including)
FreeipaRedhat2.2.1 (including)2.2.1 (including)
Red Hat Enterprise Linux 5RedHatipa-client-0:2.1.3-5.el5_9.2*
Red Hat Enterprise Linux 6RedHatipa-0:2.2.0-17.el6_3.1*
FreeipaUbuntuprecise*
FreeipaUbuntuquantal*
FreeipaUbuntuupstream*

References