Input validation error in FreeIPA - CVE-2019-14867

 

Input validation error in FreeIPA - CVE-2019-14867

Published: March 17, 2020


Vulnerability identifier: #VU26103
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2019-14867
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: freeipa.org
Affected software:
FreeIPA

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input within the ber_scanf() function when processing kerberos key data. A remote non-authenticated attacker with ability to trigger parsing of the krb principal key, can pass specially crafted krb principal key to the IPA server and crash it or execute arbitrary code on the target system.


How to mitigate CVE-2019-14867

Install updates from vendor's website.

Sources