LWN.net Logo

Advertisement

GStreamer, Embedded Linux, Android, VoD, Smooth Streaming, DRM, RTSP, HEVC, PulseAudio, OpenGL. Register now to attend.

Advertise here

pki-tps: two vulnerabilities

Package(s):pki-tps CVE #(s):CVE-2013-1885 CVE-2013-1886
Created:June 6, 2013 Updated:June 12, 2013
Description:

From the Red Hat bugzilla entries [1, 2]:

CVE-2013-1885: It was reported that Certificate System suffers from XSS flaws in the /tus/ and /tus/tus/ URLs, such as:

GET /tus/tus/%22%2b%61%6c%65%72%74%28%34%38%32%36%37%29%2b%22

or

GET /tus/%22%2b%61%6c%65%72%74%28%36%31%34%35%32%29%2b%22

which will in turn output something like:

<!--
var uriBase = "/tus/"+alert(85384)+";
var userid = "admin";

This was reported against Certificate System 8.1 and may also affect Dogtag 9 and 10.

CVE-2013-1886: It was reported that Certificate System suffers from a format string injection flaw when viewing certificates. This could allow a remote attacker to crash the Certificate System server or, possibly, execute arbitrary code with the privileges of the user [running] the service (typically run as an unprivileged user, such as pkiuser).

Alerts:
Fedora FEDORA-2013-9258 2013-06-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds