PT-2012-3097 · Red Hat+1 · Red Hat Network Satellite+2
Publicado
2012-06-16
·
Atualizado
2022-02-03
·
CVE-2012-1145
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6
Description
The issue is related to improper authorization or authentication of uploads to the NULL organization when mod wsgi is used. This allows remote attackers to cause a denial of service by consuming disk space in the /var partition and causing failed updates via a large number of package uploads.
Recommendations
For Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6, consider restricting access to the upload functionality to prevent unauthorized uploads until a proper fix is available. As a temporary workaround, monitor the /var partition disk space and update processes closely to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Red Hat Network Satellite
Mod Wsgi