CVE-2012-6119
published 2013-04-02CVE-2012-6119: Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.42%
34.3th percentile
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| candlepinproject | candlepin | <= 0.7.2 | — |
| candlepinproject | candlepin | — | — |
| candlepinproject | candlepin | — | — |
| candlepinproject | candlepin | — | — |
| candlepinproject | candlepin | — | — |
| candlepinproject | candlepin | — | — |
| redhat | subscription_asset_manager | <= 1.2.0 | — |
| redhat | subscription_asset_manager | — | — |
| redhat | subscription_asset_manager | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Candlepin: Re-enable manifest signature checking
vendor_redhat·2012-06-27·CVSS 2.1
CVE-2012-6119 [LOW] Candlepin: Re-enable manifest signature checking
Candlepin: Re-enable manifest signature checking
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
GHSA
GHSA-jffh-2rxm-9wjg: Candlepin before 0
ghsa_unreviewed·2022-05-17
CVE-2012-6119 [LOW] GHSA-jffh-2rxm-9wjg: Candlepin before 0
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0686.htmlhttp://secunia.com/advisories/52774http://www.osvdb.org/91719https://bugzilla.redhat.com/show_bug.cgi?id=908613https://github.com/candlepin/candlepin/blob/master/candlepin.spechttps://github.com/candlepin/candlepin/commit/f4d93230e58b969c506b4c9778e04482a059b08chttp://rhn.redhat.com/errata/RHSA-2013-0686.htmlhttp://secunia.com/advisories/52774http://www.osvdb.org/91719https://bugzilla.redhat.com/show_bug.cgi?id=908613https://github.com/candlepin/candlepin/blob/master/candlepin.spechttps://github.com/candlepin/candlepin/commit/f4d93230e58b969c506b4c9778e04482a059b08c
2013-04-02
Published