CVE-2016-3696
published 2017-06-13CVE-2016-3696: The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.35%
27.5th percentile
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| pulpproject | pulp | <= 2.8.4 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pulp: Leakage of CA key in pulp-qpid-ssl-cfg
vendor_redhat·2016-04-20·CVSS 5.5
CVE-2016-3696 [MEDIUM] CWE-732 pulp: Leakage of CA key in pulp-qpid-ssl-cfg
pulp: Leakage of CA key in pulp-qpid-ssl-cfg
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
It was found that the private CA key was created in a directory that is world-readable for a small amount of time. A local user could possibly use this flaw to gain access to the private key information in the file.
GHSA
GHSA-m563-8c32-w7fx: The pulp-qpid-ssl-cfg script in Pulp before 2
ghsa_unreviewed·2022-05-14
CVE-2016-3696 [MEDIUM] CWE-200 GHSA-m563-8c32-w7fx: The pulp-qpid-ssl-cfg script in Pulp before 2
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3704 pulp: Unsafe use of bash $RANDOM for NSS DB password and seed
bugzilla·2016-04-25·CVSS 5.5
CVE-2016-3704 [MEDIUM] CVE-2016-3704 pulp: Unsafe use of bash $RANDOM for NSS DB password and seed
CVE-2016-3704 pulp: Unsafe use of bash $RANDOM for NSS DB password and seed
Randy Barlow of Red Hat reports:
In working on another security issue in this same script, I noticed that
Pulp's pulp-qpid-ssl-cfg script uses bash's $RANDOM in unsafe ways. One
of them is already being fixed as part of another CVE (the TMP directory
is unsafe, CVE-2016-3696), but the other two uses are:
0) The default NSS DB password is a single value from $RANDOM,
limiting it to the strings from 0 to 32768:
https://github.com/pulp/pulp/blob/pulp-2.8.2-1/server/bin/pulp-qpid-ssl-cfg#L25 [Open URL]
1) The certutil -z flag receives a "noise file". The script uses $RANDOM to
populate a file with numbers to generate this file:
https://github.com/pulp/pulp/blob/pulp-2.8.2-1/server/bin/pulp-qpid-ssl-cfg#L97-L105
Bugzilla
CVE-2016-3696 pulp: Leakage of CA key in pulp-qpid-ssl-cfg
bugzilla·2016-04-20·CVSS 5.5
CVE-2016-3696 [MEDIUM] CVE-2016-3696 pulp: Leakage of CA key in pulp-qpid-ssl-cfg
CVE-2016-3696 pulp: Leakage of CA key in pulp-qpid-ssl-cfg
Sander Bos reports:
It was found that pulp-qpid-ssl-cfg script creates certificate files and NSS database files in world-readable unsafe temporary directory $DIR, from which is than the content copied to permanent installation directory $INST_DIR with wrongly assigned permissions, which are corrected only after the copying process is done. This bug gives attacker a time frame for stealing sensitive data.
Discussion:
Acknowledgments:
Name: Sander Bos
---
The Pulp upstream bug status is at ASSIGNED. Updating the external tracker on this bug.
---
The Pulp upstream bug priority is at Normal. Updating the external tracker on this bug.
---
The Pulp upstream bug priority is at High. Updating the external tracker on this bug.
-
https://access.redhat.com/errata/RHSA-2018:0336https://bugzilla.redhat.com/show_bug.cgi?id=1328930https://docs.pulpproject.org/user-guide/release-notes/2.8.x.html#pulp-2-8-5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YM2LCC7QBRCK4LTN5EZT5OHTVAR3MYTY/https://pulp.plan.io/issues/1854https://access.redhat.com/errata/RHSA-2018:0336https://bugzilla.redhat.com/show_bug.cgi?id=1328930https://docs.pulpproject.org/user-guide/release-notes/2.8.x.html#pulp-2-8-5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YM2LCC7QBRCK4LTN5EZT5OHTVAR3MYTY/https://pulp.plan.io/issues/1854
2017-06-13
Published