CVE-2012-5484: High severity red hat freeipa vulnerability
Published Jan 27, 2013
·Updated
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Affected Software
11 affected components
redhat Freeipa=2.0.0
redhat Freeipa=2.0.1
redhat Freeipa=2.1.0
redhat Freeipa=2.1.1
redhat Freeipa=2.1.3
redhat Freeipa=2.1.4
redhat Freeipa=2.2.1
redhat Freeipa=3.0.0
redhat Freeipa=3.0.1
redhat Freeipa=3.0.2
redhat Freeipa=3.1.1
Event History
Jan 27, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5484?
CVE-2012-5484 is considered a high-severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2012-5484?
To fix CVE-2012-5484, it is recommended to upgrade to FreeIPA version 3.1.2 or later.
3
What software versions are affected by CVE-2012-5484?
CVE-2012-5484 affects FreeIPA versions 2.x and 3.x before 3.1.2.
4
What impact does CVE-2012-5484 have on FreeIPA users?
CVE-2012-5484 allows attackers to spoof the join procedure, compromising the integrity of the FreeIPA client-server communication.
5
Is there a workaround for CVE-2012-5484?
There is no specific workaround for CVE-2012-5484 other than upgrading to a patched version.