Red Hat Certificate System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
BID:56843
Info
Red Hat Certificate System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
| Bugtraq ID: | 56843 |
| Class: | Unknown |
| CVE: |
CVE-2012-4543 CVE-2012-4555 CVE-2012-4556 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2012 12:00AM |
| Updated: | Apr 13 2015 09:23PM |
| Credit: | Red Hat, Patrick Raspante and Ryan Millay of GDC4S |
| Vulnerable: |
Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Optional 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
Red Hat Certificate System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Red Hat Certificate System is prone to multiple cross-site scripting and denial-of-service vulnerabilities.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Red Hat Certificate System is prone to multiple cross-site scripting and denial-of-service vulnerabilities.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Red Hat Certificate System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI. To exploit the denial-of-service issues, attackers can use readily available tools.
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI. To exploit the denial-of-service issues, attackers can use readily available tools.
Solution / Fix
Red Hat Certificate System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Red Hat Certificate System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
References:
References:
- Red Hat Certificate System Homepage (Red Hat)