CVE Vulnerabilities

CVE-2008-2368

Published: Jan 20, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.

Affected Software

NameVendorStart VersionEnd Version
Certificate_systemRedhat7.2 (including)7.2 (including)
Red Hat Certificate System 7.2 for RHEL 4RedHatpkisetup-0:7.2.0-7*
Red Hat Certificate System 7.2 for RHEL 4RedHatrhpki-ca-0:7.2.0-6*
Red Hat Certificate System 7.2 for RHEL 4RedHatrhpki-common-0:7.2.0-16*
Red Hat Certificate System 7.2 for RHEL 4RedHatrhpki-kra-0:7.2.0-5*
Red Hat Certificate System 7.2 for RHEL 4RedHatrhpki-ocsp-0:7.2.0-5*
Red Hat Certificate System 7.2 for RHEL 4RedHatrhpki-tks-0:7.2.0-5*
Red Hat Certificate System 7.2 for RHEL 4RedHatrhpki-tps-0:7.2.0-8*
Red Hat Certificate System 7.3RedHatpkisetup-0:7.3.0-14.el4*
Red Hat Certificate System 7.3RedHatrhpki-ca-0:7.3.0-17.el4*
Red Hat Certificate System 7.3RedHatrhpki-common-0:7.3.0-40.el4*
Red Hat Certificate System 7.3RedHatrhpki-kra-0:7.3.0-13.el4*
Red Hat Certificate System 7.3RedHatrhpki-ocsp-0:7.3.0-11.el4*
Red Hat Certificate System 7.3RedHatrhpki-ra-0:7.3.0-67.el4*
Red Hat Certificate System 7.3RedHatrhpki-tks-0:7.3.0-12.el4*
Red Hat Certificate System 7.3RedHatrhpki-tps-0:7.3.0-23.el4*
Red Hat Certificate System 7.3RedHatrhpki-util-0:7.3.0-20.el4*

References