Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Certificate_system | Redhat | 8.1 (including) | 8.1 (including) |
Dogtag_certificate_system | Redhat | 9.0 (including) | 9.0 (including) |
Dogtag_certificate_system | Redhat | 10.0 (including) | 10.0 (including) |
Red Hat Certificate System 8 | RedHat | pki-tps-0:8.1.3-5.el5pki | * |