First published: Wed Oct 24 2012(Updated: )
A denial of service flaw was found in the way token processing system of Certificate System processed interrupted token format operations. A local attacker, via suddenly interrupting the token format operation, could use this flaw to cause pki-tps infrastructure to crash with NULL pointer dereference, subsequently leading to relevant Apache httpd web server worker it to need to restart, rendering it to be unavailable for short period of time possibly halting (already) in-progress operations of other users.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Certificate System | <=8.1.1 | |
Redhat Certificate System | =7.1 | |
Redhat Certificate System | =7.2 | |
Redhat Certificate System | =7.3 | |
Redhat Certificate System | =8 | |
Redhat Certificate System | =8.0 | |
Redhat Certificate System | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.