VulnerabilityModified
CVE-2012-6119
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
LOW 2.1EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.42% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- candlepinproject/candlepin · redhat/subscription asset manager
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-0686.htmlVendor Advisory
- http://secunia.com/advisories/52774Vendor Advisory
- http://www.osvdb.org/91719
- https://bugzilla.redhat.com/show_bug.cgi?id=908613
- https://github.com/candlepin/candlepin/blob/master/candlepin.spec
- https://github.com/candlepin/candlepin/commit/f4d93230e58b969c506b4c9778e04482a059b08c
- http://rhn.redhat.com/errata/RHSA-2013-0686.htmlVendor Advisory
- http://secunia.com/advisories/52774Vendor Advisory
- http://www.osvdb.org/91719
- https://bugzilla.redhat.com/show_bug.cgi?id=908613
- https://github.com/candlepin/candlepin/blob/master/candlepin.spec
- https://github.com/candlepin/candlepin/commit/f4d93230e58b969c506b4c9778e04482a059b08c
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.