Vulnerability Name: | CVE-2012-4546 (CCN-82240) | ||||||||||||||||
Assigned: | 2012-09-04 | ||||||||||||||||
Published: | 2012-09-04 | ||||||||||||||||
Updated: | 2019-04-22 | ||||||||||||||||
Summary: | The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation Lists (CRLs) to be used and might allow remote attackers to bypass intended access restrictions via a revoked certificate. | ||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.9 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-16 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-4546 Source: CCN Type: FreeIPA Web site FreeIPA Source: REDHAT Type: Vendor Advisory RHSA-2013:0528 Source: CCN Type: BID-58083 FreeIPA CVE-2012-4546 Certificate Revocation List Security Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 870234 CVE-2012-4546 ipa: servers do not publish correct CRLs Source: XF Type: UNKNOWN freeipa-crl-security-bypass(82240) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |