CVE-2013-1886
published 2014-01-24CVE-2013-1886: Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.22%
80.7th percentile
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | certificate_system | — | — |
| redhat | dogtag_certificate_system | — | — |
| redhat | dogtag_certificate_system | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63g4-9329-q5x4: Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8
ghsa_unreviewed·2022-05-17
CVE-2013-1886 [HIGH] CWE-134 GHSA-63g4-9329-q5x4: Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates.
Red Hat
System: pki-tps format string injection
vendor_redhat·2013-05-22·CVSS 7.5
CVE-2013-1886 [HIGH] CWE-134 System: pki-tps format string injection
System: pki-tps format string injection
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [fedora-all]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-1885 [MEDIUM] CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [fedora-all]
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple s
Bugzilla
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [epel-5]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-1885 [MEDIUM] CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [epel-5]
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for pki-tps: see bloc
Bugzilla
CVE-2013-1886 Certificate System: pki-tps format string injection
bugzilla·2013-03-22·CVSS 7.5
CVE-2013-1886 [HIGH] CVE-2013-1886 Certificate System: pki-tps format string injection
CVE-2013-1886 Certificate System: pki-tps format string injection
It was reported that Certificate System suffers from a format string injection flaw when viewing certificates. This could allow a remote attacker to crash the Certificate System server or, possibly, execute arbitrary code with the privileges of the user runnin the service (typically run as an unprivileged user, such as pkiuser).
This was reported against Certificate System 8.1 and may also affect Dogtag 9 and 10.
Discussion:
Created pki-tps tracking bugs for this issue
Affects: fedora-all [bug 966189]
Affects: epel-5 [bug 966190]
---
This issue has been addressed in following products:
Red Hat Certificate System 8
Via RHSA-2013:0856 https://rhn.redhat.com/errata/RHSA-2013-0856.html
---
pki-tps-9.0.11-1.fc17 has be
http://osvdb.org/93613http://rhn.redhat.com/errata/RHSA-2013-0856.htmlhttp://www.securityfocus.com/bid/60085http://www.securitytracker.com/id/1029685https://bugzilla.redhat.com/show_bug.cgi?id=924870http://osvdb.org/93613http://rhn.redhat.com/errata/RHSA-2013-0856.htmlhttp://www.securityfocus.com/bid/60085http://www.securitytracker.com/id/1029685https://bugzilla.redhat.com/show_bug.cgi?id=924870
2014-01-24
Published