First published: Fri Apr 23 2010(Updated: )
It was found that the yum-rhn-plugin caches sensitive authentication information in the world-readable /var/spool/up2date/loginAuth.pkl file. This information could be used to download packages from Red Hat Network (Hosted or Satellite) or otherwise manipulate the package list associated with the system's profile, which could possibly prevent new errata from being installed.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Rhn-client-tools | ||
Redhat Yum-rhn-plugin | ||
Fedoraproject Fedora | ||
Redhat Enterprise Linux | =5 | |
Redhat Enterprise Linux | =5-ga | |
Redhat Enterprise Linux | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.