PT-2012-3097 · Red Hat+1 · Red Hat Network Satellite+2

Published

2012-06-16

·

Updated

2022-02-03

·

CVE-2012-1145

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6
Description The issue is related to improper authorization or authentication of uploads to the NULL organization when mod wsgi is used. This allows remote attackers to cause a denial of service by consuming disk space in the /var partition and causing failed updates via a large number of package uploads.
Recommendations For Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6, consider restricting access to the upload functionality to prevent unauthorized uploads until a proper fix is available. As a temporary workaround, monitor the /var partition disk space and update processes closely to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1145
RHSA-2012:0436

Affected Products

Red Hat
Red Hat Network Satellite
Mod Wsgi