CVE-2012-4555

6 documents5 sources
Severity
4.0MEDIUM
EPSS
0.4%
top 40.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 4
Latest updateMay 17

Description

The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-g97f-4ph3-r6fc: The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 82022-05-17
CVEList
CVE-2012-4555: The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 82013-01-04

📋Vendor Advisories

1
Red Hat
pki-tps: Temporary denial of service on interrupted token format operations2012-12-06

💬Community

2
Bugzilla
CVE-2012-4555 CVE-2012-4556 pki-tps various flaws [fedora-all]2012-12-06
Bugzilla
CVE-2012-4555 pki-tps: Temporary denial of service on interrupted token format operations2012-10-24