CVE-2016-9575
Summary
| CVE | CVE-2016-9575 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-13 13:29:00 UTC |
| Updated | 2019-10-09 23:20:00 UTC |
| Description | Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1395311 – (CVE-2016-9575) CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| FreeIPA CVE-2016-9575 Insecure File Permissions Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378104 Virtuozzo Linux Security Update for ipa-server (VZLSA-2017:0001)