Rapid7 Vulnerability & Exploit Database

RHSA-2007:0934: rhpki-util, rhpki-common, rhpki-ca security update

Back to Search

RHSA-2007:0934: rhpki-util, rhpki-common, rhpki-ca security update

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
11/06/2007
Created
07/25/2018
Added
09/12/2009
Modified
07/04/2017

Description

Updated rhpki-util, rhpki-common, and rhpki-ca packages that fix a security issue are now available for Red Hat Certificate System 7.2. This update has been rated as having moderate security impact by the Red Hat Security Response Team.

Red Hat Certificate System (RHCS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. It was found that new revocations performed while a Certificate Revocation List (CRL) was being generated could potentially cause revoked certificates at the upper end of the serial number range to not appear on the CRL for a period of time. A user who has a revoked but otherwise valid certificate could take advantage of this issue and bypass the revocation list, although in practice they would have no way of influencing which revoked certificate entries were missing or the time period. (CVE-2007-4994) The updated packages apply a bug fix for a 404 error caused by the server not handling OCSP requests in the GET method. Users of Red Hat Certificate System should upgrade to these updated packages, which contain a patch to correct this issue.

Solution(s)

  • redhat-upgrade-rhpki-ca
  • redhat-upgrade-rhpki-common
  • redhat-upgrade-rhpki-util

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;