Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-0966

Опубликовано: 24 мар. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-0966: pki-core:10.6 security update (IMPORTANT)

pki-core [10.9.4-3.0.1]

  • Remove redhat reference.

[10.9.4-3]

  • Bug # 1933146 - PKI instance creation failed with new 389-ds-base build

[10.9.4-2]

  • CVE-2021-20179: Fix unprivileged users can renew any certificate

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module pki-core:10.6 is enabled

jss

4.7.3-1.module+el8.3.0+7857+983338ee

jss-javadoc

4.7.3-1.module+el8.3.0+7857+983338ee

ldapjdk

4.22.0-1.module+el8.3.0+7857+983338ee

ldapjdk-javadoc

4.22.0-1.module+el8.3.0+7857+983338ee

pki-base

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-base-java

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-ca

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-kra

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-server

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-symkey

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-tools

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

python3-pki

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

tomcatjss

7.5.0-1.module+el8.3.0+7857+983338ee

Oracle Linux x86_64

Module pki-core:10.6 is enabled

jss

4.7.3-1.module+el8.3.0+7857+983338ee

jss-javadoc

4.7.3-1.module+el8.3.0+7857+983338ee

ldapjdk

4.22.0-1.module+el8.3.0+7857+983338ee

ldapjdk-javadoc

4.22.0-1.module+el8.3.0+7857+983338ee

pki-base

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-base-java

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-ca

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-kra

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-server

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-symkey

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

pki-tools

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

python3-pki

10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e

tomcatjss

7.5.0-1.module+el8.3.0+7857+983338ee

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 4 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 8.1
redhat
больше 4 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 8.1
nvd
больше 4 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 8.1
debian
больше 4 лет назад

A flaw was found in pki-core. An attacker who has successfully comprom ...

CVSS3: 8.1
github
около 3 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.