|
Red Hat update for Red Hat Network Satellite Server
|
|
Secunia Advisory:
|
SA31493
|
|
|
Release Date:
|
2008-08-14
|
|
Popularity:
|
1,324 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Security Bypass Cross Site Scripting Exposure of sensitive information DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Red Hat Network Satellite Server 5.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2005-4838 CVE-2006-0254 CVE-2006-0898 CVE-2007-1349 CVE-2007-1355 CVE-2007-1358 CVE-2007-2449 CVE-2007-5461 CVE-2007-6306 CVE-2008-0128 CVE-2008-2369
|
|
Description: Red Hat has issued an update for Red Hat Network Satellite Server. This fixes some vulnerabilities, which can be exploited by malicious users to disclose potentially sensitive information, and malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, and cause a DoS (Denial of Service).
For more information:
SA18485
SA18755
SA24678
SA25721
SA27398
SA27959
1) A vulnerability is caused due to the manzier.pxt XML-RPC script using a hard-coded authentication token. This can be exploited to disclose certain information (e.g. login names, email addresses, user IDs, and information about entitlements).
Solution: Update to Red Hat Network Satellite Server version 5.1.1. Updated packages are available via the Red Hat Network.
http://rhn.redhat.com
Provided and/or discovered by: 1) Reported by the vendor.
Original Advisory: https://rhn.redhat.com/errata/RHSA-2008-0630.html
Other References: SA18485:
http://secunia.com/advisories/18485/
SA18755:
http://secunia.com/advisories/18755/
SA24678:
http://secunia.com/advisories/24678/
SA25721:
http://secunia.com/advisories/25721/
SA27398:
http://secunia.com/advisories/27398/
SA27959:
http://secunia.com/advisories/27959/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|