CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:freeipa:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:2.2.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:freeipa:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:freeipa:3.1.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:44

Type Values Removed Values Added
References () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=18eea90ebb24a9c22248f0b7e18646cc6e3e3e0f - () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=18eea90ebb24a9c22248f0b7e18646cc6e3e3e0f -
References () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=31e41eea6c2322689826e6065ceba82551c565aa - () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=31e41eea6c2322689826e6065ceba82551c565aa -
References () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=91f4af7e6af53e1c6bf17ed36cb2161863eddae4 - () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=91f4af7e6af53e1c6bf17ed36cb2161863eddae4 -
References () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9 - () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9 -
References () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a40285c5a0288669b72f9d991508d4405885bffc - () http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a40285c5a0288669b72f9d991508d4405885bffc -
References () http://rhn.redhat.com/errata/RHSA-2013-0188.html - () http://rhn.redhat.com/errata/RHSA-2013-0188.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0189.html - () http://rhn.redhat.com/errata/RHSA-2013-0189.html -
References () http://www.freeipa.org/page/CVE-2012-5484 - Vendor Advisory () http://www.freeipa.org/page/CVE-2012-5484 - Vendor Advisory
References () http://www.freeipa.org/page/Releases/3.1.2 - () http://www.freeipa.org/page/Releases/3.1.2 -

Information

Published : 2013-01-27 18:55

Updated : 2024-11-21 01:44


NVD link : CVE-2012-5484

Mitre link : CVE-2012-5484

CVE.ORG link : CVE-2012-5484


JSON object : View

Products Affected

redhat

  • freeipa
CWE
CWE-310

Cryptographic Issues