René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

99 lines
3.0 KiB
JSON

{
"id": "CVE-2007-4994",
"sourceIdentifier": "secalert@redhat.com",
"published": "2007-11-06T21:46:00.000",
"lastModified": "2011-03-08T02:59:53.470",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL."
},
{
"lang": "es",
"value": "Certificate Server 7.2 en Red Hat Certificate System (RHCS) no maneja de forma adecuada nuevas revocaciones que ocurren mientras un ertificate Revocation List (CRL) est\u00e9 siendo generado, lo cual permite prevenir ciertas revocaciones de certificados desde la aparici\u00f3n del un CRL rapidamente y permitir a usuarios con certificados revocados evitar el CRL previsto."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:certificate_server:7.2:*:*:*:*:*:*:*",
"matchCriteriaId": "575AE74C-7079-49EE-BCFF-39406C4FD011"
}
]
}
]
}
],
"references": [
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0934.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/26377",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id?1020532",
"source": "secalert@redhat.com"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3405",
"source": "secalert@redhat.com"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3406",
"source": "secalert@redhat.com"
},
{
"url": "https://rhn.redhat.com/errata/RHSA-2008-0566.html",
"source": "secalert@redhat.com"
}
]
}