Vulnerability in IPA Server Affects Kerberos Key Parsing
CVE-2019-14867

8.8HIGH

Key Information:

Vendor
Red Hat
Status
Vendor
CVE Published:
27 November 2019

Summary

A vulnerability exists in the IPA server affecting various versions that improperly utilizes the ber_scanf() function for parsing Kerberos key data. An unauthenticated attacker could exploit this flaw to trigger the parsing of the krb principal key. This may lead to the IPA server crashing or, in specific scenarios, allow the execution of arbitrary code on the host server. The issue is present in versions 4.6.x prior to 4.6.7, 4.7.x prior to 4.7.4, and 4.8.x prior to 4.8.3, highlighting the need for timely updates.

Affected Version(s)

ipa all IPA 4.6.x versions before 4.6.7

ipa all IPA 4.7.x versions before 4.7.4

ipa all IPa 4.8.x versions before 4.8.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.