Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-5484 | First vendor Publication | 2013-01-27 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:A/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.9 | Attack Range | Adjacent network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 5.5 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5484 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-310 | Cryptographic Issues |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20967 | |||
Oval ID: | oval:org.mitre.oval:def:20967 | ||
Title: | RHSA-2013:0188: ipa security update (Important) | ||
Description: | The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2013:0188-01 CESA-2013:0188 CVE-2012-5484 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 6 CentOS Linux 6 | Product(s): | ipa |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20987 | |||
Oval ID: | oval:org.mitre.oval:def:20987 | ||
Title: | RHSA-2013:0189: ipa-client security update (Important) | ||
Description: | The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2013:0189-00 CESA-2013:0189 CVE-2012-5484 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | ipa-client |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:22947 | |||
Oval ID: | oval:org.mitre.oval:def:22947 | ||
Title: | ELSA-2013:0189: ipa-client security update (Important) | ||
Description: | The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013:0189-00 CVE-2012-5484 | Version: | 6 |
Platform(s): | Oracle Linux 5 | Product(s): | ipa-client |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:23303 | |||
Oval ID: | oval:org.mitre.oval:def:23303 | ||
Title: | ELSA-2013:0188: ipa security update (Important) | ||
Description: | The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013:0188-01 CVE-2012-5484 | Version: | 6 |
Platform(s): | Oracle Linux 6 | Product(s): | ipa |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27541 | |||
Oval ID: | oval:org.mitre.oval:def:27541 | ||
Title: | DEPRECATED: ELSA-2013-0189 -- ipa-client security update (important) | ||
Description: | [2.1.3-5.2] - Add missing man page option --ca-cert-file. (#878217) [2.1.3-5.1] - Fix python syntax backport issue in CVE patch. (#878217) [2.1.3-5] - Use secure method to retrieve IPA CA during client enrollment. CVE-2012-5484 (#878217) | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013-0189 CVE-2012-5484 | Version: | 4 |
Platform(s): | Oracle Linux 5 | Product(s): | ipa-client |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:27653 | |||
Oval ID: | oval:org.mitre.oval:def:27653 | ||
Title: | DEPRECATED: ELSA-2013-0188 -- ipa security update (important) | ||
Description: | [2.2.0-17.el6_3.1] - Fix changelog issue. The dist tag was in each entry and changing the build release changed history. (#878219) [2.2.0-17.el6_3] - Use a secure method to distribute the IPA CA to clients, CVE-2012-5484 (#878219) | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013-0188 CVE-2012-5484 | Version: | 4 |
Platform(s): | Oracle Linux 6 | Product(s): | ipa |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2013-0188.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2013-0189.nasl - Type : ACT_GATHER_INFO |
2013-02-24 | Name : The remote Fedora host is missing a security update. File : fedora_2013-2434.nasl - Type : ACT_GATHER_INFO |
2013-02-04 | Name : The remote Fedora host is missing a security update. File : fedora_2013-1445.nasl - Type : ACT_GATHER_INFO |
2013-01-25 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2013-0188.nasl - Type : ACT_GATHER_INFO |
2013-01-25 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20130123_ipa_client_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2013-01-25 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20130123_ipa_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2013-0189.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2013-0188.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2013-0189.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 22:58:24 |
|
2024-11-28 12:32:21 |
|
2021-05-04 12:22:33 |
|
2021-04-22 01:26:57 |
|
2020-05-23 00:35:15 |
|
2014-02-17 11:14:18 |
|
2013-05-10 22:49:23 |
|
2013-02-07 13:20:56 |
|
2013-01-31 00:19:11 |
|
2013-01-28 21:18:49 |
|
2013-01-27 21:19:15 |
|