CVE-2013-0199
published 2014-05-29CVE-2013-0199: The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.12%
79.7th percentile
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ipa: cross-realm kerberos with AD information leak
vendor_redhat·2013-01-23·CVSS 5.0
CVE-2013-0199 [MEDIUM] ipa: cross-realm kerberos with AD information leak
ipa: cross-realm kerberos with AD information leak
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
Statement: Not vulnerable. This issue did not affect the versions of ipa as shipped with Red Hat Enterprise Linux 6 as they did not include support for Cross-Realm Kerberos trusts with Active Directory.
Package: ipa (Red Hat Enterprise Linux 6) - Affected
GHSA
GHSA-3gwj-28p7-3v2r: The default LDAP ACIs in FreeIPA 3
ghsa_unreviewed·2022-05-05
CVE-2013-0199 [MEDIUM] GHSA-3gwj-28p7-3v2r: The default LDAP ACIs in FreeIPA 3
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
No detection rules found.
Bugzilla
CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
bugzilla·2013-01-23·CVSS 4.3
CVE-2013-0199 [MEDIUM] CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for freeipa: see bl
Bugzilla
CVE-2013-0199 ipa: cross-realm kerberos with AD information leak
bugzilla·2013-01-19·CVSS 5.0
CVE-2013-0199 [MEDIUM] CVE-2013-0199 ipa: cross-realm kerberos with AD information leak
CVE-2013-0199 ipa: cross-realm kerberos with AD information leak
FreeIPA 3.0 introduced a Cross-Realm Kerberos trusts with Active Directory, a feature that allows IPA administrators to create a Kerberos trust with an AD. This allows IPA users to be able to access resources in AD trusted domains and vice versa.
When the Kerberos trust is created, an outgoing and incoming keys are stored in the IPA LDAP backend (in ipaNTTrustAuthIncoming and ipaNTTrustAuthOutgoing attributes). However, the IPA LDAP ACIs allow anonymous read acess to these attributes which could allow an unprivileged and unauthenticated user to read the keys. With these keys, an attacker could craft an invented Kerberos ticket with an invented PAC, encrypt the PAC with the retrieved key, and impersonate any AD user in the I
Bugzilla
CVE-2013-0170 libvirt: use-after-free in virNetMessageFree()
bugzilla·2013-01-09·CVSS 6.8
CVE-2013-0170 [MEDIUM] CVE-2013-0170 libvirt: use-after-free in virNetMessageFree()
CVE-2013-0170 libvirt: use-after-free in virNetMessageFree()
A flaw was found in the way message freeing on connection cleanup was handled under certain error conditions. A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd or, potentially, escalate their privilages to that of libvirtd process.
Acknowledgements:
This issue was discovered by Tingting Zheng of Red Hat.
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5.
---
Created libvirt tracking bugs for this issue
Affects: fedora-all [bug 905173]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0199 https://rhn.redhat.com/errata/RHSA-2013-0199.html
---
Rel
http://osvdb.org/89539http://www.freeipa.org/page/CVE-2013-0199http://www.freeipa.org/page/Releases/3.1.2http://www.securityfocus.com/bid/57542https://exchange.xforce.ibmcloud.com/vulnerabilities/81486http://osvdb.org/89539http://www.freeipa.org/page/CVE-2013-0199http://www.freeipa.org/page/Releases/3.1.2http://www.securityfocus.com/bid/57542https://exchange.xforce.ibmcloud.com/vulnerabilities/81486
2014-05-29
Published