CVE-2013-0199
EUVD-2014-001929.05.2014, 14:19
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | freeipa | 3.0.0 |
| redhat | freeipa | 3.0.1 |
| redhat | freeipa | 3.0.2 |
| redhat | freeipa | 3.1.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References