CVE-2012-5484
Publication date 27 January 2013
Last updated 24 July 2024
Ubuntu priority
Description
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| freeipa | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|
Patch details
| Package | Patch details |
|---|---|
| freeipa |