Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2008-07-07T23:00:00

Updated: 2024-08-07T08:32:01.466Z

Reserved: 2008-04-03T00:00:00

Link: CVE-2008-1676

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-07-07T23:41:00.000

Modified: 2023-02-13T02:18:59.377

Link: CVE-2008-1676

cve-icon Redhat

Severity : Important

Publid Date: 2008-07-02T00:00:00Z

Links: CVE-2008-1676 - Bugzilla