Bug 488706 - (CVE-2009-0588) CVE-2009-0588 rhpki-ra: improper authorization checks in Cerificate System's Registration Authority
CVE-2009-0588 rhpki-ra: improper authorization checks in Cerificate System's ...
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 484828 488716
  Show dependency treegraph
Reported: 2009-03-05 06:19 EST by Tomas Hoger
Modified: 2011-10-25 15:54 EDT (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2011-10-25 15:54:05 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:1065 normal SHIPPED_LIVE Moderate: rhpki-ra security update 2009-05-26 13:13:42 EDT

  None (edit)
Description Tomas Hoger 2009-03-05 06:19:43 EST
Robert Mead reported that the Registration Authority component (rhpki-ra) of the Red Hat Certificate System / Dogtag Certificate System did not properly check agent's authorizations in some CGI scripts.

In deployments, where certificate requests are processed by multiple agent groups, agent from any group was able to approve or reject certificate requests in the queue for any other agent group, if he was able to guess request ID.

Original report: bug #484828

Affected systems:
Dogtag Certificate System
Red Hat Certificate System 7.3
Comment 2 Tomas Hoger 2009-05-14 14:23:33 EDT
Upstream SVN commit:
  svn diff -c 377 https://pki.fedoraproject.org/svn/pki/trunk/pki
Comment 3 errata-xmlrpc 2009-05-26 13:13:45 EDT
This issue has been addressed in following products:

  Red Hat Certificate System 7.3

Via RHSA-2009:1065 https://rhn.redhat.com/errata/RHSA-2009-1065.html

Note You need to log in before you can comment on or make changes to this bug.