First published: Wed Apr 20 2016(Updated: )
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =24 | |
Pulp Project | <=2.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3696 has a moderate severity rating due to the potential exposure of sensitive CA keys to local users.
To fix CVE-2016-3696, upgrade Pulp to version 2.8.5 or later to ensure the creation of certificate files in a secure environment.
CVE-2016-3696 affects Fedora 24 systems and Pulp versions up to and including 2.8.4.
CVE-2016-3696 addresses a vulnerability that allows local users to access the CA key due to insecure file permissions.
No, CVE-2016-3696 is not a risk in newer versions of Pulp beyond 2.8.5, as the issue has been resolved.