First published: Fri Mar 01 2013(Updated: )
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Katello | ||
Katello | <=1.3.2_pulpv2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6116 has been rated as a moderate severity vulnerability due to the potential for local users to alter sensitive certificate files.
To fix CVE-2012-6116, update the Katello software to version 1.3.3.pulpv2 or later to ensure proper permissions are set on the Candlepin bootstrap RPM.
CVE-2012-6116 is a permissions vulnerability that allows local users to modify important files due to incorrectly set file permissions.
The impact of CVE-2012-6116 includes the risk of local users being able to alter the Candlepin CA certificate, potentially compromising certificate integrity.
Yes, CVE-2012-6116 specifically affects versions of Katello earlier than 1.3.3.pulpv2.