CVE-2017-7509: Input Validation
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate an assertion error is triggered causing a denial of service.
Other sources
When submitting for certificate enrollment, Google Chrome cuts off the certreq field in the submission. This causes a null pointer exception that causes the CA to crash. This can also be reproduced using Firefox by directly passing the request to the servelet without the certreq field.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7509?
CVE-2017-7509 is categorized as a denial of service vulnerability.
How do I fix CVE-2017-7509?
To remediate CVE-2017-7509, update to Red Hat Certificate System version 8.1.20-1 or later.
What causes the denial of service in CVE-2017-7509?
The denial of service in CVE-2017-7509 is caused by an input validation error when handling client-provided certificates.
Which versions are affected by CVE-2017-7509?
Versions of Red Hat Certificate System before 8.1.20-1 are affected by CVE-2017-7509.
Is user action required to exploit CVE-2017-7509?
Yes, for CVE-2017-7509, user action is required as it involves submitting certificates without the certreq field.