CVE Vulnerabilities

CVE-2012-6116

Published: Mar 01, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.6 MODERATE
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.

Affected Software

NameVendorStart VersionEnd Version
KatelloKatello- (including)- (including)
Katello-configureKatello*1.3.2_pulpv2 (including)
CloudForms for RHEL 6RedHatcandlepin-0:0.7.19-3.el6cf*
CloudForms for RHEL 6RedHatkatello-0:1.1.12.2-5.el6cf*
CloudForms for RHEL 6RedHatkatello-cli-0:1.1.8-14.el6cf*
CloudForms for RHEL 6RedHatkatello-configure-0:1.1.9-13.el6cf*
CloudForms for RHEL 6RedHatkatello-selinux-0:1.1.1-5.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatcandlepin-0:0.7.24-1.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-0:1.2.1.1-1h.el6_4*
Red Hat Subscription Asset Manager 1.2RedHatkatello-configure-0:1.2.3.1-4h.el6_4*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-actionpack-1:3.0.10-12.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-activemodel-0:3.0.10-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-delayed_job-0:2.1.4-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-json-0:1.7.3-2.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rack-1:1.3.0-4.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rails_warden-0:0.5.5-2.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rdoc-0:3.8-6.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatthumbslug-0:0.0.28.1-1.el6_4*

References