CVE-2008-1676
Severity CVSS v4.0:
Pending analysis
Type:
CWE-255
Credentials Management
Publication date:
07/07/2008
Last modified:
13/02/2023
Description
Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:redhat:certificate_system:7.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:netscape:certificate_management_system:*:*:*:*:*:*:*:* | 6.2 (including) | |
cpe:2.3:a:netscape:certificate_management_system:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:netscape:certificate_management_system:6.01:*:*:*:*:*:*:* | ||
cpe:2.3:a:netscape:certificate_management_system:6.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://rhn.redhat.com/errata/RHSA-2008-0500.html
- http://rhn.redhat.com/errata/RHSA-2008-0577.html
- http://secunia.com/advisories/30929
- http://www.securityfocus.com/bid/30062
- http://www.securitytracker.com/id?1020427=
- https://bugzilla.redhat.com/show_bug.cgi?id=445227
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43573