CVE-2012-4546
published 2013-04-03CVE-2012-4546: The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.19%
64.4th percentile
The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation Lists (CRLs) to be used and might allow remote attackers to bypass intended access restrictions via a revoked certificate.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ipa: servers do not publish correct CRLs
vendor_redhat·2012-09-04·CVSS 4.3
CVE-2012-4546 [MEDIUM] ipa: servers do not publish correct CRLs
ipa: servers do not publish correct CRLs
The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation Lists (CRLs) to be used and might allow remote attackers to bypass intended access restrictions via a revoked certificate.
GHSA
GHSA-f7qj-88hv-799m: The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not pro
ghsa_unreviewed·2022-05-14
CVE-2012-4546 [MEDIUM] GHSA-f7qj-88hv-799m: The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not pro
The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation Lists (CRLs) to be used and might allow remote attackers to bypass intended access restrictions via a revoked certificate.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
bugzilla·2013-01-23·CVSS 4.3
CVE-2013-0199 [MEDIUM] CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for freeipa: see bl
Bugzilla
CVE-2012-4546 ipa: servers do not publish correct CRLs
bugzilla·2012-10-25·CVSS 4.3
CVE-2012-4546 [MEDIUM] CVE-2012-4546 ipa: servers do not publish correct CRLs
CVE-2012-4546 ipa: servers do not publish correct CRLs
It was found that the current default configuration of IPA servers did not publish correct CRLs (Certificate Revocation Lists). The default configuration specifies that every replica is to generate its own CRL, however this can result in inconsistencies in the CRL contents provided to clients from different Identity Management replicas. More specifically, if a certificate is revoked on one Identity Management replica, it will not show up on another Identity Management replica.
To avoid this inconsistency, the solution is to configure CRL generation to only take place on one Identity Management server. To do so in Red Hat Enterprise Linux 6.3 and earlier, the CRL configuration must be changed on all Identity Management servers.
Pleas
2013-04-03
Published