CVE-2010-1171: Medium severity red hat satellite vulnerability
Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.
Other sources
RHN Satellite incorrectly exposed an obsolete XML-RPC API for configuring package group (comps.xml) files for channels. An authenticated user could use this flaw to gain access to arbitrary files accessible to the RHN Satellite server process, and prevent clients from performing certain yum operations.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1171?
CVE-2010-1171 is classified as a high severity vulnerability due to its potential for unauthorized file access and denial of service.
How do I fix CVE-2010-1171?
To fix CVE-2010-1171, you should upgrade your Red Hat Network Satellite to version 5.5 or later.
Who is affected by CVE-2010-1171?
CVE-2010-1171 affects users of Red Hat Network Satellite versions 5.3 and 5.4.
What are the consequences of CVE-2010-1171?
The consequences of CVE-2010-1171 include unauthorized access to files and disrupted yum operations, leading to service denial.
Is CVE-2010-1171 explotable remotely?
Yes, CVE-2010-1171 can be exploited by remote authenticated users.