Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:3044

Опубликовано: 14 июн. 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: idm:DL1 security update

Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • freeipa: specially crafted HTTP requests potentially lead to denial of service (CVE-2024-1481)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.10 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
custodianoarch3.module+el8.9.0+1371+ffa84eb9custodia-0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm
custodianoarch3.module+el8.9.0+1371+ffa84eb9custodia-0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm
ipa-healthcheck-corenoarch3.module+el8.9.0+1433+5bd2f890ipa-healthcheck-core-0.12-3.module+el8.9.0+1433+5bd2f890.noarch.rpm
ipa-healthcheck-corenoarch3.module+el8.9.0+1433+5bd2f890ipa-healthcheck-core-0.12-3.module+el8.9.0+1433+5bd2f890.noarch.rpm
opendnssecx86_641.module+el8.9.0+1371+ffa84eb9opendnssec-2.1.7-1.module+el8.9.0+1371+ffa84eb9.x86_64.rpm
python3-custodianoarch3.module+el8.9.0+1371+ffa84eb9python3-custodia-0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm
python3-custodianoarch3.module+el8.9.0+1371+ffa84eb9python3-custodia-0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm
python3-kdcproxynoarch5.module+el8.9.0+1371+ffa84eb9python3-kdcproxy-0.4-5.module+el8.9.0+1371+ffa84eb9.noarch.rpm
python3-kdcproxynoarch5.module+el8.9.0+1371+ffa84eb9python3-kdcproxy-0.4-5.module+el8.9.0+1371+ffa84eb9.noarch.rpm
python3-pyusbnoarch9.1.module+el8.9.0+1371+ffa84eb9python3-pyusb-1.0.0-9.1.module+el8.9.0+1371+ffa84eb9.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

CVSS3: 5.3
redhat
почти 2 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

CVSS3: 5.3
nvd
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.

CVSS3: 5.3
debian
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to ...

CVSS3: 5.3
github
больше 1 года назад

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.