SB2019112649 - Fedora 31 update for freeipa
Published: November 26, 2019 Updated: April 25, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2019-10195)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to the way FreeIPA's batch is processing API logged operations that includes storing passwords in clear text on FreeIPA masters. A local user with access to system logs on FreeIPA masters can use this vulnerability to produce log file content with passwords exposed.
2) Input validation error (CVE-ID: CVE-2019-14867)
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the ber_scanf() function when processing kerberos key data. A remote non-authenticated attacker with ability to trigger parsing of the krb principal key, can pass specially crafted krb principal key to the IPA server and crash it or execute arbitrary code on the target system.
Remediation
Install update from vendor's website.