CVE-2012-6119
02.04.2013, 22:55
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.Enginsight
Vendor | Product | Version |
---|---|---|
candlepinproject | candlepin | 𝑥 ≤ 0.7.2 |
candlepinproject | candlepin | 0.4.5 |
candlepinproject | candlepin | 0.4.11 |
candlepinproject | candlepin | 0.4.27 |
candlepinproject | candlepin | 0.5.5 |
candlepinproject | candlepin | 0.6.3 |
redhat | subscription_asset_manager | 𝑥 ≤ 1.2.0 |
redhat | subscription_asset_manager | 1.0.0 |
redhat | subscription_asset_manager | 1.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References