PT-2012-3097 · Red Hat+1 · Red Hat Network Satellite+2
Published
2012-06-16
·
Updated
2022-02-03
·
CVE-2012-1145
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6
Description
The issue is related to improper authorization or authentication of uploads to the NULL organization when mod wsgi is used. This allows remote attackers to cause a denial of service by consuming disk space in the /var partition and causing failed updates via a large number of package uploads.
Recommendations
For Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6, consider restricting access to the upload functionality to prevent unauthorized uploads until a proper fix is available. As a temporary workaround, monitor the /var partition disk space and update processes closely to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Red Hat Network Satellite
Mod Wsgi