PT-2008-1084 · Red Hat · Yum-Rhn-Plugin+1
Published
2008-08-14
·
Updated
2017-09-29
·
CVE-2008-3270
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Linux (RHEL) 5
Description
The issue concerns a lack of SSL certificate verification for file downloads from a Red Hat Network (RHN) server, making it easier for remote attackers to cause a denial of service or force the download and installation of official Red Hat packages that were not requested. This could lead to a disruption in the integrity of protected information. The exploitation of this issue can be done remotely.
Recommendations
For Red Hat Enterprise Linux (RHEL) 5, update the yum-rhn-plugin to a version that verifies SSL certificates for downloads from RHN servers. As a temporary workaround, consider restricting access to RHN servers to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Yum-Rhn-Plugin