Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN.
References
Link | Resource |
---|---|
http://secunia.com/advisories/42181 | Vendor Advisory |
http://securitytracker.com/id?1024697 | |
http://www.osvdb.org/69148 | |
https://bugzilla.redhat.com/show_bug.cgi?id=648883 | |
https://fedorahosted.org/pki/changeset/1246 | Patch |
https://rhn.redhat.com/errata/RHSA-2010-0837.html | Vendor Advisory |
https://rhn.redhat.com/errata/RHSA-2010-0838.html | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2010-11-17 16:00
Updated : 2010-11-18 05:00
NVD link : CVE-2010-3869
Mitre link : CVE-2010-3869
CVE.ORG link : CVE-2010-3869
JSON object : View
Products Affected
redhat
- dogtag_certificate_system
- certificate_system
CWE
CWE-310
Cryptographic Issues