|Category:||Red Hat Local Security Checks|
|Title:||RedHat Update for yum-updatesd RHSA-2014:1004-01|
|Summary:||The remote host is missing an update for the 'yum-updatesd'; package(s) announced via the referenced advisory.|
The remote host is missing an update for the 'yum-updatesd'
package(s) announced via the referenced advisory.
The yum-updatesd package provides a daemon which checks for available
updates and can notify you when they are available via email, syslog,
It was discovered that yum-updatesd did not properly perform RPM package
signature checks. When yum-updatesd was configured to automatically install
updates, a remote attacker could use this flaw to install a malicious
update on the target system using an unsigned RPM or an RPM signed with an
untrusted key. (CVE-2014-0022)
All yum-updatesd users are advised to upgrade to this updated package,
which contains a backported patch to correct this issue. After installing
this update, the yum-updatesd service will be restarted automatically.
yum-updatesd on Red Hat Enterprise Linux (v. 5 server)
Please Install the Updated Packages.
Common Vulnerability Exposure (CVE) ID: CVE-2014-0022|
BugTraq ID: 65119
|Copyright||Copyright (C) 2014 Greenbone Networks GmbH|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.