CVE Vulnerabilities

CVE-2012-6119

Published: Apr 02, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

Affected Software

NameVendorStart VersionEnd Version
CandlepinCandlepinproject*0.7.2 (including)
CandlepinCandlepinproject0.4.5 (including)0.4.5 (including)
CandlepinCandlepinproject0.4.11 (including)0.4.11 (including)
CandlepinCandlepinproject0.4.27 (including)0.4.27 (including)
CandlepinCandlepinproject0.5.5 (including)0.5.5 (including)
CandlepinCandlepinproject0.6.3 (including)0.6.3 (including)
Subscription_asset_managerRedhat*1.2.0 (including)
Subscription_asset_managerRedhat1.0.0 (including)1.0.0 (including)
Subscription_asset_managerRedhat1.1.0 (including)1.1.0 (including)
Red Hat Subscription Asset Manager 1.2RedHatcandlepin-0:0.7.24-1.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-0:1.2.1.1-1h.el6_4*
Red Hat Subscription Asset Manager 1.2RedHatkatello-configure-0:1.2.3.1-4h.el6_4*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-actionpack-1:3.0.10-12.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-activemodel-0:3.0.10-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-delayed_job-0:2.1.4-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-json-0:1.7.3-2.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rack-1:1.3.0-4.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rails_warden-0:0.5.5-2.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rdoc-0:3.8-6.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatthumbslug-0:0.0.28.1-1.el6_4*

References