Candidate: CVE-2016-5404 PublicDate: 2016-09-07 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5404 Description: The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission. Ubuntu-Description: It was discovered that FreeIPA incorrectly handled certificates. An attacker could possibly use this issue to cause a denial of service by revoking arbitrary certificates. Notes: Bugs: https://fedorahosted.org/freeipa/ticket/6232 Priority: low Discovered-by: Fraser Tweedale Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_freeipa: upstream: https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=cf74584d0f772f3f5eccc1d30c001e4212a104fd upstream_freeipa: released (4.4.1) precise_freeipa: ignored (reached end-of-life) precise/esm_freeipa: DNE (precise was needs-triage) trusty_freeipa: not-affected (code not present) trusty/esm_freeipa: not-affected (code not present) vivid/stable-phone-overlay_freeipa: DNE vivid/ubuntu-core_freeipa: DNE xenial_freeipa: ignored (end of standard support, was needed) yakkety_freeipa: ignored (reached end-of-life) zesty_freeipa: not-affected (4.4.3-3ubuntu2.1) artful_freeipa: not-affected (4.4.3-3ubuntu2.1) bionic_freeipa: not-affected (4.4.3-3ubuntu2.1) cosmic_freeipa: not-affected (4.4.3-3ubuntu2.1) disco_freeipa: not-affected (4.4.3-3ubuntu2.1) eoan_freeipa: not-affected (4.4.3-3ubuntu2.1) focal_freeipa: not-affected (4.4.3-3ubuntu2.1) groovy_freeipa: not-affected (4.4.3-3ubuntu2.1) hirsute_freeipa: not-affected (4.4.3-3ubuntu2.1) impish_freeipa: not-affected (4.4.3-3ubuntu2.1) jammy_freeipa: not-affected (4.4.3-3ubuntu2.1) devel_freeipa: not-affected (4.4.3-3ubuntu2.1)