CVE-2013-1886: High severity red hat certificate system vulnerability
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates.
Other sources
It was reported that Certificate System suffers from a format string injection flaw when viewing certificates. This could allow a remote attacker to crash the Certificate System server or, possibly, execute arbitrary code with the privileges of the user runnin the service (typically run as an unprivileged user, such as pkiuser).
This was reported against Certificate System 8.1 and may also affect Dogtag 9 and 10.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1886?
CVE-2013-1886 has a moderate severity level, allowing for potential denial of service and arbitrary code execution.
How do I fix CVE-2013-1886?
To fix CVE-2013-1886, upgrade to pki-tps version 8.1.5-1.el5 or later, and ensure you are using a patched version of the affected Dogtag Certificate System.
Who is affected by CVE-2013-1886?
CVE-2013-1886 affects remote authenticated users of Red Hat Certificate System 8.1 and Dogtag Certificate Systems 9 and 10.
What kind of attack does CVE-2013-1886 enable?
CVE-2013-1886 enables remote authenticated users to exploit a format string vulnerability potentially leading to a denial of service or arbitrary code execution.
Is CVE-2013-1886 under active exploitation?
As of the last update, there have been no confirmed reports of active exploitation for CVE-2013-1886.