Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 304571 - (CVE-2007-4994) CVE-2007-4994 rhcs CRL can get corrupted
CVE-2007-4994 rhcs CRL can get corrupted
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
source=redhat,impact=moderate,reporte...
: Security
Depends On: 243176 304581 304591
Blocks:
  Show dependency treegraph
 
Reported: 2007-09-25 04:12 EDT by Mark J. Cox
Modified: 2008-01-14 11:19 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-01-14 11:19:19 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:0934 normal SHIPPED_LIVE Moderate: rhpki-util, rhpki-common, rhpki-ca security update 2007-10-08 03:44:34 EDT
Red Hat Product Errata RHSA-2008:0566 normal SHIPPED_LIVE Moderate: rhpki-util, rhpki-common, and rhpki-ca security and bug fix update 2008-07-21 15:16:51 EDT

  None (edit)
Description Mark J. Cox 2007-09-25 04:12:30 EDT
New revocations performed while a CRL is being generated
could potentially cause revoked certificates at the upper
end of the serial number range to not appear on the CRL.

In subsequent CRLs, those missing certificates could again
appear on the CRL.
Comment 2 Mark J. Cox 2007-09-25 04:15:51 EDT
CVSS base score 3.6:

AccessVector: Network
AccessComplexity: High (you have no way of making a particular certificate
become unrevoked, just chance)
Authentication: Single (you need an otherwise valid but revoked certificate)
ConfImpact: Partial
AvailImpact: None
IntegImpact: Partial

Comment 5 Mark J. Cox 2007-10-08 03:31:55 EDT
removing embargo.
Comment 6 Red Hat Product Security 2008-01-14 11:19:19 EST
This issue was addressed in:

Red Hat Certificate System:
  http://rhn.redhat.com/errata/RHSA-2007-0934.html


Note You need to log in before you can comment on or make changes to this bug.