Vulnerability Bulletins |
Salto de restricciones en RedHat Certificate Server |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | GNU/Linux |
| Affected software | rhpki-util, rhpki-common y rhpki-ca de RedHat Certificate Server 7.2 y 7.3 |
Description |
|
|
Se ha descubierto una vulnerabilidad en rhpki-util, rhpki-common y rhpki-ca de RedHat Certificate Server 7.2 y 7.3. La vulnerabilidad reside en un error al procesar nuevas revocaciones cuando se está generando la lista de revocación de certificados (CRL). Un atacante remoto con un certificado revocado podría saltarse la lista de revocación de certificados. |
|
Solution |
|
|
Actualización de software Red Hat (RHSA-2008:0547-5) Certificate Server 7.3 https://rhn.redhat.com/ |
|
Standar resources |
|
| Property | Value |
| CVE | CVE-2007-4994 |
| BID | 26377 |
Other resources |
|
|
Red Hat Security Advisory (RHSA-2008:0566-7) https://rhn.redhat.com/errata/RHSA-2008-0566.html |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2008-07-22 |






