CVE-2019-14867: Code Injection
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function berscanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.
Other sources
A flaw was found in the way the internal function berscanf() was used in some components of the IPA server which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key, could cause the IPA server to crash or in some conditions cause arbitrary code to be executed on the server hosting the IPA server.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14867?
CVE-2019-14867 is classified as a moderate severity vulnerability due to the potential for an unauthenticated attacker to exploit it.
How do I fix CVE-2019-14867?
To fix CVE-2019-14867, upgrade FreeIPA to version 4.6.7, 4.7.4, or 4.8.3 or later.
Which versions of FreeIPA are affected by CVE-2019-14867?
CVE-2019-14867 affects FreeIPA versions prior to 4.6.7, 4.7.4, and 4.8.3.
Can CVE-2019-14867 be exploited remotely?
Yes, CVE-2019-14867 can be exploited remotely by an unauthenticated attacker.
What components of FreeIPA are impacted by CVE-2019-14867?
CVE-2019-14867 impacts the internal function ber_scanf() used to parse kerberos key data in the IPA server.