PT-2011-1364 · Red Hat · Red Hat Network Satellite

Vincent Danen

·

Published

2011-04-18

·

Updated

2022-02-19

·

CVE-2010-1171

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Network (RHN) Satellite versions 5.3 through 5.4
Description The issue allows remote authenticated users to access arbitrary files and cause a denial of service, specifically failed yum operations, via vectors related to configuration and package group (comps.xml) files for channels. This is due to the exposure of a dangerous, obsolete XML-RPC API.
Recommendations For versions 5.3 and 5.4, consider disabling the obsolete XML-RPC API as a temporary workaround until a patch is available. Restrict access to configuration and package group files, such as comps.xml, to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1171
RHSA-2011:0434

Affected Products

Red Hat Network Satellite