USN-4792-1

Source
https://ubuntu.com/security/notices/USN-4792-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4792-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4792-1
Related
Published
2021-03-15T21:13:01.388465Z
Modified
2021-03-15T21:13:01.388465Z
Summary
freeipa vulnerabilities
Details

It was discovered that FreeIPA incorrectly handled certificates. An attacker could possibly use this issue to cause a denial of service by revoking arbitrary certificates This issue only affected Ubuntu 16.04 ESM. (CVE-2016-5404)

It was discovered that FreeIPA incorrectly handled authentication attempts. An attacker could possibly use this issue to cause a denial of service. (CVE-2016-7030)

It was discovered that FreeIPA incorrectly handled user's permissions. An authenticated attacker could possibly use this issue to modify other user's profiles or other unspecified impact. This issue only affected Ubuntu 16.04 ESM. (CVE-2016-9575)

References

Affected packages

Ubuntu:Pro:14.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.4-0ubuntu3.1+esm1

Affected versions

3.*

3.2.1-0ubuntu1
3.3.4-0ubuntu1
3.3.4-0ubuntu2
3.3.4-0ubuntu3
3.3.4-0ubuntu3.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.3.4-0ubuntu3.1+esm1",
            "binary_name": "freeipa-client"
        },
        {
            "binary_version": "3.3.4-0ubuntu3.1+esm1",
            "binary_name": "freeipa-client-dbgsym"
        },
        {
            "binary_version": "3.3.4-0ubuntu3.1+esm1",
            "binary_name": "python-freeipa"
        },
        {
            "binary_version": "3.3.4-0ubuntu3.1+esm1",
            "binary_name": "python-freeipa-dbgsym"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.1-0ubuntu1+esm1

Affected versions

4.*

4.1.4-1
4.3.1-0ubuntu1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-admintools"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-client"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-client-dbgsym"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-common"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-server"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-server-dbgsym"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-server-dns"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-server-trust-ad"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-server-trust-ad-dbgsym"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "freeipa-tests"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "python-ipaclient"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "python-ipalib"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "python-ipaserver"
        },
        {
            "binary_version": "4.3.1-0ubuntu1+esm1",
            "binary_name": "python-ipatests"
        }
    ]
}