{
  "threat_severity" : "Important",
  "public_date" : "2019-08-26T00:00:00Z",
  "bugzilla" : {
    "description" : "ipa: Denial of service in IPA server due to wrong use of ber_scanf()",
    "id" : "1766920",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1766920"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-134",
  "details" : [ "A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.", "A flaw was found in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server." ],
  "statement" : "This flaw can be exploited by an unauthenticated attacker (PR:N) who could create a specially crafted \"krbPrincipalKey\" and send it to the IPA server (AV:N).  The attack is relatively easy to conduct (AC:L), since all the attacker requires is a string which is long enough to write beyond the limits of the buffer on the stack. User interaction is required for the attack (UI:N). End result in a crash in the IPA server causing denial of service or in some conditions may also result  in remote code execution with the permissions of the user running the IPA server (CIA:H).",
  "acknowledgement" : "Red Hat would like to thank Todd Lipcon (Cloudera) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2020-02-04T00:00:00Z",
    "advisory" : "RHSA-2020:0378",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "ipa-0:4.6.5-11.el7_7.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2019-12-17T00:00:00Z",
    "advisory" : "RHBA-2019:4268",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "idm:DL1-8010020191127093529.6573b795"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions",
    "release_date" : "2020-04-01T00:00:00Z",
    "advisory" : "RHSA-2020:1269",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.0",
    "package" : "idm:DL1-8000020200217171713.2874843d"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Virtualization 4",
    "fix_state" : "Not affected",
    "package_name" : "redhat-virtualization-host",
    "cpe" : "cpe:/o:redhat:rhev_hypervisor:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-14867\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-14867\nhttps://www.freeipa.org/page/Releases/4.6.7\nhttps://www.freeipa.org/page/Releases/4.7.4\nhttps://www.freeipa.org/page/Releases/4.8.3" ],
  "name" : "CVE-2019-14867",
  "csaw" : false
}