RHEL 6 : ipa (RHSA-2011:1533)

This script is Copyright (C) 2011-2014 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing one or more security updates.

Description :

Updated ipa packages that fix one security issue and several bugs are
now available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having
moderate security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from
the CVE link in the References section.

Red Hat Identity Management is a centralized authentication, identity
management and authorization solution for both traditional and cloud
based enterprise environments. It integrates components of the Red Hat
Directory Server, MIT Kerberos, Red Hat Certificate System, NTP and
DNS. It provides web browser and command-line interfaces. Its
administration tools allow an administrator to quickly install, set
up, and administer a group of domain controllers to meet the
authentication and identity management requirements of large scale
Linux and UNIX deployments.

A Cross-Site Request Forgery (CSRF) flaw was found in Red Hat Identity
Management. If a remote attacker could trick a user, who was logged
into the management web interface, into visiting a specially-crafted
URL, the attacker could perform Red Hat Identity Management
configuration changes with the privileges of the logged in user.
(CVE-2011-3636)

Due to the changes required to fix CVE-2011-3636, client tools will
need to be updated for client systems to communicate with updated Red
Hat Identity Management servers. New client systems will need to have
the updated ipa-client package installed to be enrolled. Already
enrolled client systems will need to have the updated certmonger
package installed to be able to renew their system certificate. Note
that system certificates are valid for two years by default.

Updated ipa-client and certmonger packages for Red Hat Enterprise
Linux 6 were released as part of Red Hat Enterprise Linux 6.2. Future
updates will provide updated packages for Red Hat Enterprise Linux 5.

This update includes several bug fixes. Space precludes documenting
all of these changes in this advisory. Users are directed to the Red
Hat Enterprise Linux 6.2 Technical Notes for information on the most
significant of these changes, linked to in the References section.

Users of Red Hat Identity Management should upgrade to these updated
packages, which correct these issues.

See also :

https://www.redhat.com/security/data/cve/CVE-2011-3636.html
https://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/
http://rhn.redhat.com/errata/RHSA-2011-1533.html

Solution :

Update the affected packages.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.6
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Red Hat Local Security Checks

Nessus Plugin ID: 57014 ()

Bugtraq ID: 50930

CVE ID: CVE-2011-3636