Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1024697 | |
https://fedorahosted.org/pki/changeset/1246 | Patch |
http://secunia.com/advisories/42181 | Vendor Advisory |
https://rhn.redhat.com/errata/RHSA-2010-0837.html | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=648883 | |
http://www.osvdb.org/69148 | |
https://rhn.redhat.com/errata/RHSA-2010-0838.html | Vendor Advisory |
Information
Published : 2010-11-17 08:00
Updated : 2010-11-17 21:00
NVD link : CVE-2010-3869
Mitre link : CVE-2010-3869
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
redhat
- certificate_system
- dogtag_certificate_system