PT-2018-4346 · Red Hat · Red Hat Network Client Tools+2
Jan Bee
·
Published
2018-04-12
·
Updated
2019-04-22
·
CVE-2015-1777
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Network Client Tools versions on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7
Description
The issue is related to the
rhnreg ks component in Red Hat Network Client Tools, which fails to properly validate hostnames in X.509 certificates from SSL servers. This allows remote attackers to launch a man-in-the-middle attack, preventing system registration.Recommendations
For Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7, update the Red Hat Network Client Tools to a version that properly validates hostnames in X.509 certificates.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Red Hat Gluster Storage
Red Hat Network Client Tools