Fedora 16 : ca-certificates-2011.78-1.fc16 (2011-11907)

high Nessus Plugin ID 56106

Synopsis

The remote Fedora host is missing a security update.

Description

This update includes the latest updates to the root Certificate Authority list from Mozilla.

It was found that a Certificate Authority (CA) issued fraudulent HTTPS certificates. This update removes that CA's root certificate from the ca-certificates package, rendering any HTTPS certificates signed by that CA as untrusted.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected ca-certificates package.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=734679

http://www.nessus.org/u?d2d6bc25

Plugin Details

Severity: High

ID: 56106

File Name: fedora_2011-11907.nasl

Version: 1.8

Type: local

Agent: unix

Published: 9/7/2011

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:ca-certificates, cpe:/o:fedoraproject:fedora:16

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 9/1/2011

Reference Information

FEDORA: 2011-11907