Sicherheit: Ausführen beliebiger Kommandos in freeipa
Name: Ausführen beliebiger Kommandos in freeipa
ID: FEDORA-2020-8ab66bddc1
Distribution: Fedora
Plattformen: Fedora 31
Datum: So, 5. April 2020, 17:00
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1938
Applikationen: FreeIPA


Fedora Update Notification
2020-04-05 03:03:00.010430

Name : freeipa
Product : Fedora 31
Version : 4.8.6
Release : 1.fc31
URL : http://www.freeipa.org/
Summary : The Identity, Policy and Audit system
Description :
IPA is an integrated solution to provide centrally managed Identity (users,
hosts, services), Authentication (SSO, 2FA), and Authorization
(host access control, SELinux user roles, services). The solution provides
features for further integration with Linux based clients (SUDO, automount)
and integration with Active Directory based infrastructures (Trusts).

Update Information:

New upstream release. Please see release notes at
https://www.freeipa.org/page/Releases/4.8.6 and
https://www.freeipa.org/page/Releases/4.8.5 for full list of changes since
FreeIPA 4.8.4. Major highlights: * openDNSSEC 2.1 support (not enabled on
Fedora 31) * AJP connector protection for Dogtag/FreeIPA communication for
CVE-2020-1938 mitigation. Fedora and RHEL do not force encrypted AJP connector
by default with 9.0.31 but FreeIPA 4.8.5 will convert to encrypted AJP channel
on upgrade or at a new deployment. Use of AJP is limited to localhost
connections with integrated CA already. * Default authentication indicators are
now documented in FreeIPA workshop,
* FreeIPA SELinux policy is now part of the upstream packaging and replaces
distribution-wide policies. * New internal mechanism to promote Trust Agents in
ipa-adtrust-install, to allow configuring schema compatibility plugin on remote
replicas. * New "ipa-cacert-manage delete" command to allow pruning a
certificate from LDAP store

* Fri Mar 27 2020 Alexander Bokovoy <abokovoy@redhat.com> - 4.8.6-1
- Upstream release FreeIPA 4.8.6

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-8ab66bddc1' at the command
line. For more information, refer to the dnf documentation available at

