Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-3867

Опубликовано: 06 авг. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

РелизСтатусПримечание
devel

released

2.7.11-1ubuntu3
hardy

ignored

end of life
lucid

released

0.25.4-2ubuntu6.8
natty

released

2.6.4-2ubuntu2.10
oneiric

released

2.7.1-1ubuntu3.7
precise

released

2.7.11-1ubuntu2.1
upstream

released

2.6.17,2.7.18

Показывать по

EPSS

Процентиль: 80%
0.01418
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

nvd
больше 13 лет назад

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

debian
больше 13 лет назад

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2. ...

github
больше 8 лет назад

Pupper does not properly restrict characters in Common Name field of Certificate Signing Request

EPSS

Процентиль: 80%
0.01418
Низкий

4.3 Medium

CVSS2