Vulnerability Name: | CVE-2019-14867 (CCN-172282) | ||||||||||||||||||||||||
Assigned: | 2019-08-26 | ||||||||||||||||||||||||
Published: | 2019-08-26 | ||||||||||||||||||||||||
Updated: | 2020-02-05 | ||||||||||||||||||||||||
Summary: | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server. | ||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-400 CWE-94 CWE-94 CWE-400 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-14867 Source: CCN Type: FreeIPA Web site FreeIPA Source: REDHAT Type: UNKNOWN RHBA-2019:4268 Source: REDHAT Type: UNKNOWN RHSA-2020:0378 Source: CCN Type: Red Hat Bugzilla Bug 1766920 (CVE-2019-14867) - CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14867 Source: XF Type: UNKNOWN ipa-cve201914867-code-exec(172282) Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2019-c64e1612f5 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2019-8e9093da55 Source: MISC Type: Release Notes https://www.freeipa.org/page/Releases/4.6.7 Source: MISC Type: Release Notes https://www.freeipa.org/page/Releases/4.7.4 Source: MISC Type: Release Notes https://www.freeipa.org/page/Releases/4.8.3 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |