PT-2013-1904 · Red Hat · Candlepin+1

Kurt Seifried

·

Published

2013-04-02

·

Updated

2013-04-03

·

CVE-2012-6119

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Candlepin versions prior to 0.7.24 Red Hat Subscription Asset Manager versions prior to 1.2.1
Description The issue is related to the improper checking of manifest signatures, allowing local users to modify manifests.
Recommendations For Candlepin versions prior to 0.7.24, update to version 0.7.24 or later. For Red Hat Subscription Asset Manager versions prior to 1.2.1, update to version 1.2.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6119

Affected Products

Candlepin
Red Hat Subscription Asset Manager