CVE Vulnerabilities

CVE-2007-4994

Published: Nov 06, 2007 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL.

Affected Software

Name Vendor Start Version End Version
Certificate_server Redhat 7.2 (including) 7.2 (including)
Red Hat Certificate System 7.2 for RHEL 4 RedHat rhpki-ca-0:7.2.0-4 *
Red Hat Certificate System 7.2 for RHEL 4 RedHat rhpki-common-0:7.2.0-8 *
Red Hat Certificate System 7.2 for RHEL 4 RedHat rhpki-util-0:7.2.0-4 *
Red Hat Certificate System 7.3 RedHat rhpki-ca-0:7.3.0-11.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-common-0:7.3.0-34.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-util-0:7.3.0-18.el4 *

References