2.1
CVSSv2

CVE-2012-6119

Published: 02/04/2013 Updated: 03/04/2013
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Candlepin prior to 0.7.24, as used in Red Hat Subscription Asset Manager prior to 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

candlepinproject candlepin 0.5.5

candlepinproject candlepin 0.4.27

candlepinproject candlepin 0.4.11

candlepinproject candlepin 0.4.5

redhat subscription asset manager 1.1.0

candlepinproject candlepin

redhat subscription asset manager

redhat subscription asset manager 1.0.0

candlepinproject candlepin 0.6.3

Vendor Advisories

Synopsis Moderate: Subscription Asset Manager 121 update Type/Severity Security Advisory: Moderate Topic Red Hat Subscription Asset Manager 121, which fixes several securityissues, multiple bugs, and adds various enhancements, is now availableThe Red Hat Security Response Team has rated this update as ...