Bug 1026998 (CVE-2013-4518)
Summary: | CVE-2013-4518 RHUI: PKI entitlement certificates are world readable | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Kurt Seifried <kseifried> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | ccoleman, dmcphers, jialiu, jmatthew, lmeyer, mmcgrath, security-response-team, tsanders |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2015-08-22 15:30:55 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1026828 | ||
Bug Blocks: |
Description
Kurt Seifried
2013-11-05 20:41:40 UTC
OpenShift Online does not appear to be affected: [appname-username.rhcloud.com 012345678901234567890123]\> cat /etc/pki/entitlement/content-rhel6.key cat: /etc/pki/entitlement/content-rhel6.key: Permission denied [appname-username.rhcloud.com 012345678901234567890123]\> cat /etc/pki/entitlement/rhui-client-config-server-6.key cat: /etc/pki/entitlement/rhui-client-config-server-6.key: Permission denied Statement: Red Hat Update Infrastructure 2.1.3 is now in Production 2 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Update Infrastructure Life Cycle: https://access.redhat.com/support/policy/updates/rhui. |