Bug 304571 - (CVE-2007-4994) CVE-2007-4994 rhcs CRL can get corrupted
CVE-2007-4994 rhcs CRL can get corrupted
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 243176 304581 304591
  Show dependency treegraph
Reported: 2007-09-25 04:12 EDT by Mark J. Cox (Product Security)
Modified: 2008-01-14 11:19 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-01-14 11:19:19 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Mark J. Cox (Product Security) 2007-09-25 04:12:30 EDT
New revocations performed while a CRL is being generated
could potentially cause revoked certificates at the upper
end of the serial number range to not appear on the CRL.

In subsequent CRLs, those missing certificates could again
appear on the CRL.
Comment 2 Mark J. Cox (Product Security) 2007-09-25 04:15:51 EDT
CVSS base score 3.6:

AccessVector: Network
AccessComplexity: High (you have no way of making a particular certificate
become unrevoked, just chance)
Authentication: Single (you need an otherwise valid but revoked certificate)
ConfImpact: Partial
AvailImpact: None
IntegImpact: Partial

Comment 5 Mark J. Cox (Product Security) 2007-10-08 03:31:55 EDT
removing embargo.
Comment 6 Red Hat Product Security 2008-01-14 11:19:19 EST
This issue was addressed in:

Red Hat Certificate System:

Note You need to log in before you can comment on or make changes to this bug.