CVE-2012-5484
published 2013-01-27CVE-2012-5484: The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows…
PriorityP429high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
0.56%
42.8th percentile
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| freeipa | freeipa | < 18eea90ebb24a9c22248f0b7e18646cc6e3e3e0f | 18eea90ebb24a9c22248f0b7e18646cc6e3e3e0f |
| freeipa | freeipa | < a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9 | a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9 |
| freeipa | freeipa | < 31e41eea6c2322689826e6065ceba82551c565aa | 31e41eea6c2322689826e6065ceba82551c565aa |
| freeipa | freeipa | < a40285c5a0288669b72f9d991508d4405885bffc | a40285c5a0288669b72f9d991508d4405885bffc |
| freeipa | freeipa | >= 0 < 91f4af7e6af53e1c6bf17ed36cb2161863eddae4 | 91f4af7e6af53e1c6bf17ed36cb2161863eddae4 |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
CVSS provenance
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6rr4-9qrg-g6j5: The client in FreeIPA 2
ghsa_unreviewed·2022-05-17
CVE-2012-5484 [HIGH] GHSA-6rr4-9qrg-g6j5: The client in FreeIPA 2
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
OSV
CVE-2012-5484: The client in FreeIPA 2
osv·2013-01-27
CVE-2012-5484 CVE-2012-5484: The client in FreeIPA 2
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Red Hat
ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
vendor_redhat·2013-01-23·CVSS 7.9
CVE-2012-5484 [HIGH] ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain [fedora-all]
bugzilla·2013-01-23·CVSS 7.9
CVE-2012-5484 [HIGH] CVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain [fedora-all]
CVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when a
Bugzilla
CVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
bugzilla·2012-11-13·CVSS 7.9
CVE-2012-5484 [HIGH] CVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
CVE-2012-5484 ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
A weakness was found in the way an IPA client would communicate with an IPA server when attempting to join an IPA domain.
When an IPA client attempted to join an IPA domain, and if an attacker were able to spoof the DNS name of the IPA server, the client would connect to the attacker's fake server. The attacker would be able to intercept the credentials from the client, and issue commands to the server using these credentials, with their privilege. A join initiated by an administrative user would grant the attacker administrative rights to the IPA server, whereas a join initiated by an unprivileged user would only grant the attacker limited privilege (typically just the ability to join
http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=18eea90ebb24a9c22248f0b7e18646cc6e3e3e0fhttp://git.fedorahosted.org/cgit/freeipa.git/commit/?id=31e41eea6c2322689826e6065ceba82551c565aahttp://git.fedorahosted.org/cgit/freeipa.git/commit/?id=91f4af7e6af53e1c6bf17ed36cb2161863eddae4http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a40285c5a0288669b72f9d991508d4405885bffchttp://rhn.redhat.com/errata/RHSA-2013-0188.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0189.htmlhttp://www.freeipa.org/page/CVE-2012-5484http://www.freeipa.org/page/Releases/3.1.2http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=18eea90ebb24a9c22248f0b7e18646cc6e3e3e0fhttp://git.fedorahosted.org/cgit/freeipa.git/commit/?id=31e41eea6c2322689826e6065ceba82551c565aahttp://git.fedorahosted.org/cgit/freeipa.git/commit/?id=91f4af7e6af53e1c6bf17ed36cb2161863eddae4http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a40285c5a0288669b72f9d991508d4405885bffchttp://rhn.redhat.com/errata/RHSA-2013-0188.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0189.htmlhttp://www.freeipa.org/page/CVE-2012-5484http://www.freeipa.org/page/Releases/3.1.2
2013-01-27
Published