REDHAT-BUG-913751: Medium severity freeipa vulnerability
Sumit Bose discovered that FreeIPA's directory server (dirsrv) would segfault if an unauthenicated user attempted to connect to it with a missing username/dn. According to RFC 3062, connecting without specifying the username/dn is valid.
Acknowledgements:
This issue was discovered by Sumit Bose of Red Hat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-913751?
The severity of REDHAT-BUG-913751 is classified as a denial-of-service vulnerability due to the directory server segfault on an unauthenticated connection attempt.
How do I fix REDHAT-BUG-913751?
To fix REDHAT-BUG-913751, apply the latest security updates provided by Red Hat for FreeIPA.
What versions of FreeIPA are affected by REDHAT-BUG-913751?
REDHAT-BUG-913751 affects all versions of Red Hat FreeIPA prior to the security patch.
Can an unauthenticated user exploit REDHAT-BUG-913751?
Yes, an unauthenticated user can exploit REDHAT-BUG-913751 by attempting to connect without specifying a username or DN.
Is connecting without a username or DN allowed according to standards in REDHAT-BUG-913751?
Yes, connecting without specifying a username or DN is valid per RFC 3062, which makes this vulnerability particularly concerning.