CVE Vulnerabilities

CVE-2012-6119

Published: Apr 02, 2013 | Modified: Apr 03, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

Affected Software

Name Vendor Start Version End Version
Candlepin Candlepinproject * 0.7.2 (including)
Candlepin Candlepinproject 0.4.5 (including) 0.4.5 (including)
Candlepin Candlepinproject 0.4.11 (including) 0.4.11 (including)
Candlepin Candlepinproject 0.4.27 (including) 0.4.27 (including)
Candlepin Candlepinproject 0.5.5 (including) 0.5.5 (including)
Candlepin Candlepinproject 0.6.3 (including) 0.6.3 (including)
Subscription_asset_manager Redhat * 1.2.0 (including)
Subscription_asset_manager Redhat 1.0.0 (including) 1.0.0 (including)
Subscription_asset_manager Redhat 1.1.0 (including) 1.1.0 (including)
Red Hat Subscription Asset Manager 1.2 RedHat candlepin-0:0.7.24-1.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-0:1.2.1.1-1h.el6_4 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-configure-0:1.2.3.1-4h.el6_4 *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-actionpack-1:3.0.10-12.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-activemodel-0:3.0.10-3.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-delayed_job-0:2.1.4-3.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-json-0:1.7.3-2.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-rack-1:1.3.0-4.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-rails_warden-0:0.5.5-2.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-rdoc-0:3.8-6.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat thumbslug-0:0.0.28.1-1.el6_4 *

References