CVE Vulnerabilities

CVE-2012-2092

Improper Verification of Cryptographic Signature

Published: Dec 06, 2019 | Modified: Dec 17, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Ubuntu_cobbler Canonical * 2.2.2 (excluding)
Cobbler Ubuntu devel *
Cobbler Ubuntu oneiric *
Cobbler Ubuntu precise *
Cobbler Ubuntu quantal *
Cobbler Ubuntu raring *

References