ipa: Denial of service in IPA server due to wrong use of ber_scanf()
Published Nov 27, 2019
8.7
HIGHCVSS 4.0
EPSS 7.41%
Description
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.
Affected products
-
- Version all IPA 4.6.x versions before 4.6.7StatusaffectedConstraints-
- Version all IPA 4.7.x versions before 4.7.4StatusaffectedConstraints-
- Version all IPa 4.8.x versions before 4.8.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 30
- 31
No data.
Red Hat Enterprise Linux 7
ipa-0:4.6.5-11.el7_7.4
Fixed · RHSA-2020:0378
Red Hat Enterprise Linux 8
idm:DL1-8010020191127093529.6573b795
Fixed · RHBA-2019:4268
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
idm:DL1-8000020200217171713.2874843d
Fixed · RHSA-2020:1269
Red Hat Enterprise Linux 6
ipa
Out of support scope
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | ipa-0:4.6.5-11.el7_7.4 | Fixed | RHSA-2020:0378 |
| Red Hat Enterprise Linux 8 | idm:DL1-8010020191127093529.6573b795 | Fixed | RHBA-2019:4268 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | idm:DL1-8000020200217171713.2874843d | Fixed | RHSA-2020:1269 |
| Red Hat Enterprise Linux 6 | ipa | Out of support scope | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw can be exploited by an unauthenticated attacker (PR:N) who could create a specially crafted "krbPrincipalKey" and send it to the IPA server (AV:N). The attack is relatively easy to conduct (AC:L), since all the attacker requires is a string which is long enough to write beyond the limits of the buffer on the stack. User interaction is required for the attack (UI:N). End result in a crash in the IPA server causing denial of service or in some conditions may also result in remote code execution with the permissions of the user running the IPA server (CIA:H).
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 7.41% (0.07413) | 94.27th | v5 (v2026.06.15) |
| Jul 24, 2026 | 7.35% (0.07353) | 93.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.33% (0.06329) | 92.71th | v5 (v2026.06.15) |
| Jul 7, 2025 | 2.73% (0.02727) | 85.31th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.54% (0.01542) | 79.66th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.82% (0.03822) | 79.98th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.54% (0.01542) | 80.09th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.28% (0.01278) | 86.30th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.07% (0.01067) | 82.49th | v3 (v2023.03.01) |
| Sep 16, 2023 | 1.41% (0.01408) | 84.90th | v3 (v2023.03.01) |
| Apr 16, 2023 | 1.34% (0.01345) | 84.09th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.54% (0.01542) | 85.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.94% (0.02945) | 83.32th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.94% (0.02945) | 81.62th | v2 (v2022.01.01) |
| Feb 4, 2022 | 25.42% (0.25423) | 95.54th | v2 (v2022.01.01) |
| Feb 3, 2022 | 13.06% (0.13061) | 88.99th | v1 |
| Jan 6, 2022 | 13.06% (0.13061) | 88.86th | v1 |
| Sep 1, 2021 | 3.24% (0.03240) | 81.50th | v1 |
| Apr 14, 2021 | 3.24% (0.03240) | 0.00th | v1 |
References (17)
- https://access.redhat.com/errata/RHBA-2019:4268 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0378 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-14867 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1766920 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14867 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-7hpj-hfcr-5qwm Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ipa/PYSEC-2019-28.yaml
- https://github.com/pypa/advisory-db/tree/main/vulns/ipa/PYSEC-2019-28.yaml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67SEUWJAJ5RMH5K4Q6TS2I7HIMXUGNKF/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLFL5XDCJ3WT6JCLCQVKHZBLHGW7PW4T/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/67SEUWJAJ5RMH5K4Q6TS2I7HIMXUGNKF
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLFL5XDCJ3WT6JCLCQVKHZBLHGW7PW4T
- https://nvd.nist.gov/vuln/detail/CVE-2019-14867
- https://www.cve.org/CVERecord?id=CVE-2019-14867
- https://www.freeipa.org/page/Releases/4.6.7 x_refsource_MISCRelease Notes
- https://www.freeipa.org/page/Releases/4.7.4 x_refsource_MISCRelease Notes
- https://www.freeipa.org/page/Releases/4.8.3 x_refsource_MISCRelease Notes
Change history (0)
No recorded changes yet.