Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN.
References
Link | Resource |
---|---|
http://secunia.com/advisories/42181 | Vendor Advisory |
http://securitytracker.com/id?1024697 | |
http://www.osvdb.org/69148 | |
https://bugzilla.redhat.com/show_bug.cgi?id=648883 | |
https://fedorahosted.org/pki/changeset/1246 | Patch |
https://rhn.redhat.com/errata/RHSA-2010-0837.html | Vendor Advisory |
https://rhn.redhat.com/errata/RHSA-2010-0838.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2010-11-17T15:00:00Z
Updated: 2010-11-17T15:00:00Z
Reserved: 2010-10-08T00:00:00Z
Link: CVE-2010-3869
JSON object: View
NVD Information
Status : Analyzed
Published: 2010-11-17T16:00:01.920
Modified: 2010-11-18T05:00:00.000
Link: CVE-2010-3869
JSON object: View
Redhat Information
No data.
CWE