PT-2009-1191 · Red Hat · Red Hat Certificate System

Tomas Hoger

·

Publicado

2009-01-20

·

Atualizado

2017-08-08

·

CVE-2008-2368

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Certificate System version 7.2
Description The issue allows local users to discover passwords by reading certain log files. This is due to the storage of passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and other unspecified debug log files. Additionally, the weak permissions set for these files contribute to the problem.
Recommendations For Red Hat Certificate System version 7.2, consider restricting access to the log files to minimize the risk of exploitation. As a temporary workaround, change the permissions of the affected log files to prevent unauthorized access until a more permanent solution is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2368
RHSA-2009:0006
RHSA-2009:0007

Produtos afetados

Red Hat Certificate System