PT-2014-3448 · Red Hat +1 · Yum +2

Published

2014-06-02

·

Updated

2023-02-13

·

CVE-2014-0041

CVSS v2.0
4.3
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N

Name of the Vulnerable Software and Affected Versions:

OpenStack Heat Templates (heat-templates) as used in Red Hat Enterprise Linux OpenStack Platform version 4.0

Description:

The issue allows man-in-the-middle attackers to prevent updates via unspecified vectors by disabling SSL protection for certain Yum repositories.

Recommendations:

For Red Hat Enterprise Linux OpenStack Platform version 4.0, consider enabling SSL verification for Yum repositories to prevent man-in-the-middle attacks.

Fix

Weakness Enumeration

Related Identifiers

CVE-2014-0041
RHSA-2014:0579

Affected Products

Openstack Heat Templates
Red Hat Enterprise Linux Openstack Platform
Yum