Vulnerabilities > CVE-2012-5484 - Cryptographic Issues vulnerability in Redhat Freeipa

047910
CVSS 7.9 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE

Summary

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Signature Spoofing by Key Recreation
    An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.

Nessus

  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2013-0189.NASL
    descriptionAn updated ipa-client package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. Red Hat Identity Management is a centralized authentication, identity management and authorization solution for both traditional and cloud-based enterprise environments. A weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-06-01
    modified2020-06-02
    plugin id63676
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/63676
    titleRHEL 5 : ipa-client (RHSA-2013:0189)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-1445.NASL
    descriptionUpdate to upstream 3.1.2 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-02-04
    plugin id64419
    published2013-02-04
    reporterThis script is Copyright (C) 2013-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/64419
    titleFedora 18 : freeipa-3.1.2-1.fc18 (2013-1445)
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2013-0188.NASL
    descriptionFrom Red Hat Security Advisory 2013:0188 : Updated ipa packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. Red Hat Identity Management is a centralized authentication, identity management and authorization solution for both traditional and cloud-based enterprise environments. A weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-06-01
    modified2020-06-02
    plugin id68714
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/68714
    titleOracle Linux 6 : ipa (ELSA-2013-0188)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2013-0188.NASL
    descriptionUpdated ipa packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. Red Hat Identity Management is a centralized authentication, identity management and authorization solution for both traditional and cloud-based enterprise environments. A weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-06-01
    modified2020-06-02
    plugin id63675
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/63675
    titleRHEL 6 : ipa (RHSA-2013:0188)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20130123_IPA_CLIENT_ON_SL5_X.NASL
    descriptionA weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-03-18
    modified2013-01-25
    plugin id64090
    published2013-01-25
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/64090
    titleScientific Linux Security Update : ipa-client on SL5.x i386/x86_64 (20130123)
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2013-0189.NASL
    descriptionFrom Red Hat Security Advisory 2013:0189 : An updated ipa-client package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. Red Hat Identity Management is a centralized authentication, identity management and authorization solution for both traditional and cloud-based enterprise environments. A weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-06-01
    modified2020-06-02
    plugin id68715
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/68715
    titleOracle Linux 5 : ipa-client (ELSA-2013-0189)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-2434.NASL
    descriptionUpdate to upstream 2.2.1 GA. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-02-24
    plugin id64855
    published2013-02-24
    reporterThis script is Copyright (C) 2013-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/64855
    titleFedora 17 : freeipa-2.2.2-1.fc17 (2013-2434)
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2013-0188.NASL
    descriptionUpdated ipa packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. Red Hat Identity Management is a centralized authentication, identity management and authorization solution for both traditional and cloud-based enterprise environments. A weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-06-01
    modified2020-06-02
    plugin id64081
    published2013-01-25
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/64081
    titleCentOS 6 : ipa (CESA-2013:0188)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20130123_IPA_ON_SL6_X.NASL
    descriptionA weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-03-18
    modified2013-01-25
    plugin id64091
    published2013-01-25
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/64091
    titleScientific Linux Security Update : ipa on SL6.x i386/x86_64 (20130123)
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2013-0189.NASL
    descriptionAn updated ipa-client package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. Red Hat Identity Management is a centralized authentication, identity management and authorization solution for both traditional and cloud-based enterprise environments. A weakness was found in the way IPA clients communicated with IPA servers when initially attempting to join IPA domains. As there was no secure way to provide the IPA server
    last seen2020-06-01
    modified2020-06-02
    plugin id63673
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/63673
    titleCentOS 5 : ipa-client (CESA-2013:0189)

Redhat

advisories
  • bugzilla
    id876307
    titleCVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
    oval
    OR
    • commentRed Hat Enterprise Linux must be installed
      ovaloval:com.redhat.rhba:tst:20070304026
    • AND
      • commentRed Hat Enterprise Linux 6 is installed
        ovaloval:com.redhat.rhba:tst:20111656003
      • OR
        • AND
          • commentipa-python is earlier than 0:2.2.0-17.el6_3.1
            ovaloval:com.redhat.rhsa:tst:20130188001
          • commentipa-python is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhsa:tst:20111533004
        • AND
          • commentipa-client is earlier than 0:2.2.0-17.el6_3.1
            ovaloval:com.redhat.rhsa:tst:20130188003
          • commentipa-client is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20194268026
        • AND
          • commentipa-admintools is earlier than 0:2.2.0-17.el6_3.1
            ovaloval:com.redhat.rhsa:tst:20130188005
          • commentipa-admintools is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhsa:tst:20111533010
        • AND
          • commentipa-server is earlier than 0:2.2.0-17.el6_3.1
            ovaloval:com.redhat.rhsa:tst:20130188007
          • commentipa-server is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20194268018
        • AND
          • commentipa-server-selinux is earlier than 0:2.2.0-17.el6_3.1
            ovaloval:com.redhat.rhsa:tst:20130188009
          • commentipa-server-selinux is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhsa:tst:20111533006
    rhsa
    idRHSA-2013:0188
    released2013-01-23
    severityImportant
    titleRHSA-2013:0188: ipa security update (Important)
  • bugzilla
    id876307
    titleCVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
    oval
    OR
    • commentRed Hat Enterprise Linux must be installed
      ovaloval:com.redhat.rhba:tst:20070304026
    • AND
      • commentRed Hat Enterprise Linux 5 is installed
        ovaloval:com.redhat.rhba:tst:20070331005
      • commentipa-client is earlier than 0:2.1.3-5.el5_9.2
        ovaloval:com.redhat.rhsa:tst:20130189001
      • commentipa-client is signed with Red Hat redhatrelease key
        ovaloval:com.redhat.rhsa:tst:20130189002
    rhsa
    idRHSA-2013:0189
    released2013-01-23
    severityImportant
    titleRHSA-2013:0189: ipa-client security update (Important)
rpms
  • ipa-admintools-0:2.2.0-17.el6_3.1
  • ipa-client-0:2.2.0-17.el6_3.1
  • ipa-debuginfo-0:2.2.0-17.el6_3.1
  • ipa-python-0:2.2.0-17.el6_3.1
  • ipa-server-0:2.2.0-17.el6_3.1
  • ipa-server-selinux-0:2.2.0-17.el6_3.1
  • ipa-client-0:2.1.3-5.el5_9.2
  • ipa-client-debuginfo-0:2.1.3-5.el5_9.2