Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Red Hat Enterprise Linux 7: RHSA-2021-5195-02 Moderate: ipa Security Fix

red hat
Calendar Grey December 16, 2021
Dist Redhat Esm H88
A recent update for Red Hat Enterprise Linux 7 has been released, targeting a moderate security vulnerability associated with samba. For more information, please refer to the details provided.
An update for ipa is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.
Security Fix(es):
* samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets (CVE-2020-25719)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server (BZ#2025848)

References

https://access.redhat.com/security/cve/CVE-2020-25719 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: ipa-4.6.8-5.el7_9.10.src.rpm
noarch: ipa-client-common-4.6.8-5.el7_9.10.noarch.rpm ipa-common-4.6.8-5.el7_9.10.noarch.rpm ipa-python-compat-4.6.8-5.el7_9.10.noarch.rpm python2-ipaclient-4.6.8-5.el7_9.10.noarch.rpm python2-ipalib-4.6.8-5.el7_9.10.noarch.rpm
x86_64: ipa-client-4.6.8-5.el7_9.10.x86_64.rpm ipa-debuginfo-4.6.8-5.el7_9.10.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
noarch: ipa-server-common-4.6.8-5.el7_9.10.noarch.rpm ipa-server-dns-4.6.8-5.el7_9.10.noarch.rpm python2-ipaserver-4.6.8-5.el7_9.10.noarch.rpm
x86_64: ipa-debuginfo-4.6.8-5.el7_9.10.x86_64.rpm ipa-server-4.6.8-5.el7_9.10.x86_64.rpm ipa-server-trust-ad-4.6.8-5.el7_9.10.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source: ipa-4.6.8-5.el7_9.10.src.rpm
noarch: ipa-client-common-4.6.8-5.el7_9.10.noarch.rpm ipa-common-4.6.8-5.el7_9.10.noarch.rpm ipa-python-compat-4.6.8-5.el7_9.10.noarch.rpm python2-ipaclient-4.6.8-5.el7_9.10.noarch.rpm python2-ipalib-4.6.8-5.el7_9.10.noarch.rpm
x86_64: ipa-client-4.6.8-5.el7_9.10.x86_64.rpm ipa-debuginfo-4.6.8-5.el7_9.10.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
noarch: ipa-server-common-4.6.8-5.el7_9.10.noarch.rpm ipa-server-dns-4.6.8-5.el7_9.10.noarch.rpm

Read the Full Advisory


Advisory ID: RHSA-2021:5195-01
Product: Red Hat Enterprise Linux
Issue date: 2021-12-16

Topic

An update for ipa is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64

Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64

Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64

Bugs Fixed

2019732 - CVE-2020-25719 samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets

2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here