Oval Definition:oval:com.ubuntu.precise:def:20143250000
Revision Date:2014-12-31Version:1
Title:CVE-2014-3250 on Ubuntu 12.04 LTS (precise) - low.
Description:In Apache 2.4, SSLCARevocationCheck directive was added to mod_ssl, which defaults it to none and must be explicitly configured. This setting enables checking of a certificate revocation list. The default Puppet master vhost config shipped with Puppet does not include this setting. If a Puppet master is set up to run with Apache 2.4, and this default vhost configuration file is used, the Puppet master will continue to honor a host's certificate even after it is revoked.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-3250
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND While related to the CVE in some way, the 'puppet' package in precise is not affected (note: 'apache 2.2').
  • BACK