CVE-2016-3095
published 2017-06-08CVE-2016-3095: server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.30%
22.3th percentile
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| pulpproject | pulp | <= 2.8.1 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pulp: Potential leakage when generating new CA key in /tmp
vendor_redhat·2016-03-31·CVSS 5.5
CVE-2016-3095 [MEDIUM] CWE-200 pulp: Potential leakage when generating new CA key in /tmp
pulp: Potential leakage when generating new CA key in /tmp
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
Statement: This issue did not affect the versions of pulp as shipped with Red Hat Satellite 6.x and Red Hat Update Infrastructure 2.x as they did not include support for pulp-gen-ca-certificate.
Package: pulp (Red Hat Satellite 6) - Not affected
GHSA
GHSA-rgm2-v748-933h: server/bin/pulp-gen-ca-certificate in Pulp before 2
ghsa_unreviewed·2022-05-17
CVE-2016-3095 [MEDIUM] CWE-200 GHSA-rgm2-v748-933h: server/bin/pulp-gen-ca-certificate in Pulp before 2
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3106 pulp: Insecure creation of temporary directory when generating new CA key
bugzilla·2016-04-07·CVSS 5.5
CVE-2016-3106 [MEDIUM] CVE-2016-3106 pulp: Insecure creation of temporary directory when generating new CA key
CVE-2016-3106 pulp: Insecure creation of temporary directory when generating new CA key
It was found that fix for CVE-2016-3095 was incomplete, introducing new vulnerabilities due to insecure way of creating the temporary directory when generating new CA key.
Discussion:
Acknowledgments:
Name: Florian Weimer (Red Hat), Sander Bos
---
Created attachment 1144778
Proposed patch
---
For the record, Sander Bos has also independently reported this issue to the Pulp team. Thanks to both Florian and Sander!
---
Created attachment 1145757
Second patch proposal
Sander Bos recommended also setting the umask on the patch, which I think is a good addition to the patch. I am attaching that version of the patch here as well.
---
Created attachment 1145973
Second patch proposal
Here is the s
Bugzilla
CVE-2016-3095 pulp: Potential leakage when generating new CA key in /tmp
bugzilla·2016-03-31·CVSS 5.5
CVE-2016-3095 [MEDIUM] CVE-2016-3095 pulp: Potential leakage when generating new CA key in /tmp
CVE-2016-3095 pulp: Potential leakage when generating new CA key in /tmp
It was found that newly generated CA keys by running pulp-gen-ca-certificate (which is run by spec file when pulp is installed) script are insufficiently protected against reading by other users for the time the script runs.
Vulnerable code:
https://github.com/pulp/pulp/blob/2.8.0/server/bin/pulp-gen-ca-certificate
Discussion:
Acknowledgments:
Name: Randy Barlow (Red Hat)
---
This upstream pull request fixes this issue and also raises the size of the default CA key:
https://github.com/pulp/pulp/pull/2503
---
Satellite 6's use of Pulp does not utilize certificate based authentication to Pulp's API, we only authenticate via OAuth so it appears that our product is not vulnerable to this CVE.
---
IRC conversa
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182006.htmlhttp://www.openwall.com/lists/oss-security/2016/04/06/3http://www.openwall.com/lists/oss-security/2016/04/18/11https://bugzilla.redhat.com/show_bug.cgi?id=1322706https://github.com/pulp/pulp/pull/2503/commits/9f969b94c4b4f310865455d36db207de6cffebcahttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/182006.htmlhttp://www.openwall.com/lists/oss-security/2016/04/06/3http://www.openwall.com/lists/oss-security/2016/04/18/11https://bugzilla.redhat.com/show_bug.cgi?id=1322706https://github.com/pulp/pulp/pull/2503/commits/9f969b94c4b4f310865455d36db207de6cffebca
2017-06-08
Published