First published: Fri May 26 2017(Updated: )
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate an assertion error is triggered causing a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/pki-common | <8.1.20-1.el5 | 8.1.20-1.el5 |
Red Hat Certificate System | <8.1.20-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7509 is categorized as a denial of service vulnerability.
To remediate CVE-2017-7509, update to Red Hat Certificate System version 8.1.20-1 or later.
The denial of service in CVE-2017-7509 is caused by an input validation error when handling client-provided certificates.
Versions of Red Hat Certificate System before 8.1.20-1 are affected by CVE-2017-7509.
Yes, for CVE-2017-7509, user action is required as it involves submitting certificates without the certreq field.