PT-2013-1196 · Red Hat · Subscription-Manager-Gui+5

Florian Weimer

+1

·

Published

2013-05-06

·

Updated

2017-08-29

·

CVE-2012-6137

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux subscription-manager versions 1.0.24.1 through 1.1.23.1 Red Hat Enterprise Linux subscription-manager-debuginfo versions 1.0.24.1 through 1.1.23.1 Red Hat Enterprise Linux subscription-manager-gui versions 1.0.24.1 through 1.1.23.1 Red Hat Enterprise Linux subscription-manager-migration versions 1.0.24.1 through 1.1.23.1 Red Hat Enterprise Linux subscription-manager-firstboot versions 1.0.24.1 through 1.1.23.1
Description The issue is related to the rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager, which does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network. This allows remote man-in-the-middle attackers to obtain sensitive information, such as user credentials. The exploitation of this issue can be done remotely and may lead to the disruption of protected information integrity.
Recommendations For Red Hat Enterprise Linux subscription-manager versions 1.0.24.1 through 1.1.23.1, update the subscription-manager package to a version that includes the fix for this issue. For Red Hat Enterprise Linux subscription-manager-debuginfo versions 1.0.24.1 through 1.1.23.1, update the subscription-manager-debuginfo package to a version that includes the fix for this issue. For Red Hat Enterprise Linux subscription-manager-gui versions 1.0.24.1 through 1.1.23.1, update the subscription-manager-gui package to a version that includes the fix for this issue. For Red Hat Enterprise Linux subscription-manager-migration versions 1.0.24.1 through 1.1.23.1, update the subscription-manager-migration package to a version that includes the fix for this issue. For Red Hat Enterprise Linux subscription-manager-firstboot versions 1.0.24.1 through 1.1.23.1, update the subscription-manager-firstboot package to a version that includes the fix for this issue. As a temporary workaround, consider disabling the rhn-migrate-classic-to-rhsm tool until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07736
BDU:2015-07737
BDU:2015-07738
BDU:2015-07739
BDU:2015-07740
BDU:2015-07741
BDU:2015-07742
BDU:2015-07743
BDU:2015-07744
BDU:2015-07745
CVE-2012-6137
RHSA-2013:0788
RHSA-2013_0788

Affected Products

Red Hat
Subscription-Manager
Subscription-Manager-Debuginfo
Subscription-Manager-Firstboot
Subscription-Manager-Gui
Subscription-Manager-Migration