First published: Wed Jul 27 2016(Updated: )
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeIPA | =4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5414 is rated as a medium severity vulnerability.
To fix CVE-2016-5414, upgrade FreeIPA to a version that includes the patch for this vulnerability.
CVE-2016-5414 affects FreeIPA version 4.4.0.
CVE-2016-5414 is a security bug that allows remote attackers to request arbitrary SAN names for services.
Yes, CVE-2016-5414 could potentially be exploited to impersonate services through arbitrary SAN name requests.