Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 5 product line. The current stable release is 5.10. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 768058

Summary: ipa-client: Requires client-side changes for server-side fixes (due to CVE-2011-3636) [rhel-5.7.z]
Product: Red Hat Enterprise Linux 5 Reporter: RHEL Program Management <pm-rhel>
Component: ipa-clientAssignee: Rob Crittenden <rcritten>
Status: CLOSED ERRATA QA Contact: IDM QE LIST <seceng-idm-qe-list>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 5.8CC: bressers, ckannan, cww, dpal, grajaiya, nsoman, pm-eus, rcritten, security-response-team, vdanen
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: ipa-client-2.0-14.el5_7.2 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-12-20 08:16:08 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 752226    
Bug Blocks:    

Description RHEL Program Management 2011-12-15 16:30:03 UTC
This bug has been copied from bug #752226 and has been proposed
to be backported to 5.7 z-stream (EUS).

Comment 4 Rob Crittenden 2011-12-15 16:58:43 UTC
Rebased and applied patch from upstream.

Comment 6 Namita Soman 2011-12-16 15:35:11 UTC
Verified using ipa-client-2.0-14.el5_7.2

First installed client using ipa-client-2.0-14.el5_7.1, and got the error -  Missing or invalid HTTP Referer, missing.

Then upgraded to ipa-client-2.0-14.el5_7.2, and was able to install successfully.

Since 5.7 doesn't have ipa-admintools, not verifying the error by running cmd:
ipa user-show <user>

Comment 7 errata-xmlrpc 2011-12-20 08:16:08 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2011-1841.html