PT-2018-4346 · Red Hat · Red Hat Network Client Tools+2
Jan Bee
·
Publicado
2018-04-12
·
Atualizado
2019-04-22
·
CVE-2015-1777
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Network Client Tools versions on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7
Description
The issue is related to the
rhnreg ks component in Red Hat Network Client Tools, which fails to properly validate hostnames in X.509 certificates from SSL servers. This allows remote attackers to launch a man-in-the-middle attack, preventing system registration.Recommendations
For Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7, update the Red Hat Network Client Tools to a version that properly validates hostnames in X.509 certificates.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Red Hat Gluster Storage
Red Hat Network Client Tools