#VU26103 Input validation error in FreeIPA - CVE-2019-14867

 

#VU26103 Input validation error in FreeIPA - CVE-2019-14867

Published: March 17, 2020


Vulnerability identifier: #VU26103
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2019-14867
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
FreeIPA
Software vendor:
freeipa.org

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input within the ber_scanf() function when processing kerberos key data. A remote non-authenticated attacker with ability to trigger parsing of the krb principal key, can pass specially crafted krb principal key to the IPA server and crash it or execute arbitrary code on the target system.


Remediation

Install updates from vendor's website.

External links