PT-2018-4346 · Red Hat · Red Hat Network Client Tools+2

Jan Bee

·

Publicado

2018-04-12

·

Atualizado

2019-04-22

·

CVE-2015-1777

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Network Client Tools versions on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7
Description The issue is related to the rhnreg ks component in Red Hat Network Client Tools, which fails to properly validate hostnames in X.509 certificates from SSL servers. This allows remote attackers to launch a man-in-the-middle attack, preventing system registration.
Recommendations For Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7, update the Red Hat Network Client Tools to a version that properly validates hostnames in X.509 certificates. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-1777

Produtos afetados

Red Hat
Red Hat Gluster Storage
Red Hat Network Client Tools