Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.870991
Categoría:Red Hat Local Security Checks
Título:RedHat Update for subscription-manager RHSA-2013:0788-01
Resumen:The remote host is missing an update for the 'subscription-manager'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'subscription-manager'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The subscription-manager packages provide programs and libraries to allow
users to manage subscriptions and yum repositories from the Red Hat
Entitlement platform.

It was discovered that the rhn-migrate-classic-to-rhsm tool did not verify
the Red Hat Network Classic server's X.509 certificate when migrating
system profiles registered with Red Hat Network Classic to
Certificate-based Red Hat Network. An attacker could use this flaw to
conduct man-in-the-middle attacks, allowing them to obtain the user's Red
Hat Network credentials. (CVE-2012-6137)

This issue was discovered by Florian Weimer of the Red Hat Product Security
Team.

All users of subscription-manager are advised to upgrade to these updated
packages, which contain a backported patch to fix this issue.

Affected Software/OS:
subscription-manager on Red Hat Enterprise Linux (v. 5 server),
Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-6137
1028520
http://www.securitytracker.com/id/1028520
53330
http://secunia.com/advisories/53330
59674
http://www.securityfocus.com/bid/59674
93058
http://osvdb.org/93058
RHSA-2013:0788
http://rhn.redhat.com/errata/RHSA-2013-0788.html
https://bugzilla.redhat.com/show_bug.cgi?id=885130
redhat-ssl-cve20126137-sec-bypass(84020)
https://exchange.xforce.ibmcloud.com/vulnerabilities/84020
CopyrightCopyright (C) 2013 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.