Summary: | CVE-2014-3250 puppet: certificates could be honored even when revoked | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Murray McAllister <mmcallis> | ||||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||||
Status: | CLOSED ERRATA | QA Contact: | |||||||
Severity: | medium | Docs Contact: | |||||||
Priority: | medium | ||||||||
Version: | unspecified | CC: | abaron, apevec, bkearney, cbillett, ccoleman, chrisw, cpelland, dmcphers, gkotton, gmollett, jialiu, jokerman, jorton, katello-bugs, lhh, lmeyer, markmc, mmccomas, mmccune, mmcgrath, rbryant, sclewis, security-response-team, srevivo, tomckay | ||||||
Target Milestone: | --- | Keywords: | Security | ||||||
Target Release: | --- | ||||||||
Hardware: | All | ||||||||
OS: | Linux | ||||||||
Whiteboard: | |||||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2021-10-20 10:44:42 UTC | Type: | --- | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Bug Depends On: | 1107897, 1108503 | ||||||||
Bug Blocks: | 1101348 | ||||||||
Attachments: |
|
Description
Murray McAllister
2014-05-27 03:06:40 UTC
Created attachment 899367 [details]
upstream patch
Created attachment 902402 [details]
revised upstream patch
(In reply to Murray McAllister from comment #6) > Created attachment 902402 [details] > revised upstream patch A revision was not needed here. It is OK for it to be identical to the obsoleted patch. This issue was fixed in upstream version Puppet 3.6.2. External References: http://puppetlabs.com/security/cve/CVE-2014-3250 Created puppet tracking bugs for this issue: Affects: fedora-all [bug 1107897] Statement: Not vulnerable. This issue did not affect the versions of puppet as shipped with Red Hat Subscription Asset Manager 1.3 as they did not include puppet-server. |