CVE

Id
60146  
CVE No.
CVE-2013-0199  
Status
Candidate  
Description
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.  
Phase
Assigned (20121206)  
Votes
None (candidate not yet proposed)  
Comments