Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14867

Опубликовано: 26 авг. 2019
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

A flaw was found in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

Отчет

This flaw can be exploited by an unauthenticated attacker (PR:N) who could create a specially crafted "krbPrincipalKey" and send it to the IPA server (AV:N). The attack is relatively easy to conduct (AC:L), since all the attacker requires is a string which is long enough to write beyond the limits of the buffer on the stack. User interaction is required for the attack (UI:N). End result in a crash in the IPA server causing denial of service or in some conditions may also result in remote code execution with the permissions of the user running the IPA server (CIA:H).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ipaOut of support scope
Red Hat Virtualization 4redhat-virtualization-hostNot affected
Red Hat Enterprise Linux 7ipaFixedRHSA-2020:037804.02.2020
Red Hat Enterprise Linux 8idmFixedRHBA-2019:426817.12.2019
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsidmFixedRHSA-2020:126901.04.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1766920ipa: Denial of service in IPA server due to wrong use of ber_scanf()

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
nvd
около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.

CVSS3: 8.8
debian
около 6 лет назад

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x ve ...

CVSS3: 8.8
github
около 4 лет назад

Code injection in FreeIPA

oracle-oval
около 6 лет назад

ELSA-2020-0378: ipa security and bug fix update (IMPORTANT)

8.8 High

CVSS3