PT-2009-1190 · Red Hat · Red Hat Certificate System

Tomas Hoger

·

Published

2009-01-20

·

Updated

2017-08-08

·

CVE-2008-2367

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Certificate System version 7.2
Description The issue allows local users to discover passwords by reading configuration files due to world-readable permissions.
Recommendations For Red Hat Certificate System version 7.2, change the permissions of the password.conf and other configuration files to restrict read access to authorized users.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2367
RHSA-2009:0006
RHSA-2009:0007

Affected Products

Red Hat Certificate System