Описание
ELSA-2017-0001: ipa security update (MODERATE)
[4.4.0-14.0.1.el7_3.1.1]
- Blank out header-logo.png product-name.png Replace login-screen-logo.png [20362818]
[4.4.0-14.1.1]
- Resolves: #1370493 CVE-2016-7030 ipa: DoS attack against kerberized services
by abusing password policy
- ipa-kdb: search for password policies globally
- Renamed patches 1011 and 1012 to 0146 and 0145, as they were merged upstream
[4.4.0-14.1]
- Resolves: #1370493 CVE-2016-7030 ipa: DoS attack against kerberized services
by abusing password policy
- password policy: Add explicit default password policy for hosts and services
- Resolves: #1395311 CVE-2016-9575 ipa: Insufficient permission check in
certprofile-mod
- certprofile-mod: correctly authorise config update
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
ipa-admintools
4.4.0-14.0.1.el7_3.1.1
ipa-client
4.4.0-14.0.1.el7_3.1.1
ipa-client-common
4.4.0-14.0.1.el7_3.1.1
ipa-common
4.4.0-14.0.1.el7_3.1.1
ipa-python-compat
4.4.0-14.0.1.el7_3.1.1
ipa-server
4.4.0-14.0.1.el7_3.1.1
ipa-server-common
4.4.0-14.0.1.el7_3.1.1
ipa-server-dns
4.4.0-14.0.1.el7_3.1.1
ipa-server-trust-ad
4.4.0-14.0.1.el7_3.1.1
python2-ipaclient
4.4.0-14.0.1.el7_3.1.1
python2-ipalib
4.4.0-14.0.1.el7_3.1.1
python2-ipaserver
4.4.0-14.0.1.el7_3.1.1
Связанные CVE
Связанные уязвимости
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not ...
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.