Oval Definition:oval:com.ubuntu.xenial:def:201725900000000
Revision Date:2018-07-27Version:1
Title:CVE-2017-2590 on Ubuntu 16.04 LTS (xenial) - medium.
Description:A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-2590
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • NOT freeipa-admintools package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT freeipa-client package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT freeipa-common package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT freeipa-server package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT freeipa-server-dns package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT freeipa-server-trust-ad package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT freeipa-tests package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT python-ipaclient package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT python-ipalib package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT python-ipaserver package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • OR NOT python-ipatests package in xenial, while related to the CVE in some way, is not affected (note: 'code not present').
  • BACK