PT-2008-1084 · Red Hat · Yum-Rhn-Plugin+1

Publicado

2008-08-14

·

Atualizado

2017-09-29

·

CVE-2008-3270

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux (RHEL) 5
Description The issue concerns a lack of SSL certificate verification for file downloads from a Red Hat Network (RHN) server, making it easier for remote attackers to cause a denial of service or force the download and installation of official Red Hat packages that were not requested. This could lead to a disruption in the integrity of protected information. The exploitation of this issue can be done remotely.
Recommendations For Red Hat Enterprise Linux (RHEL) 5, update the yum-rhn-plugin to a version that verifies SSL certificates for downloads from RHN servers. As a temporary workaround, consider restricting access to RHN servers to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07746
CVE-2008-3270
RHSA-2008:0815
RHSA-2008_0815

Produtos afetados

Red Hat
Yum-Rhn-Plugin