CVE-2011-0717: Medium severity red hat satellite vulnerability
A session fixation flaw was found in the way Red Hat Network (RHN) Satellite and Spacewalk services handled session cookies. An RHN Satellite or Spacewalk Server user able to pre-set the session cookie in a victim's browser to a valid value could use this flaw to hijack the victim's session after the next log in.
References: [1] http://en.wikipedia.org/wiki/Sessionfixation [2] http://shiflett.org/articles/session-fixation
Acknowledgements:
Red Hat would like to thank Thomas Biege of the SuSE Security Team for reporting this issue.
Other sources
Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0717?
CVE-2011-0717 is classified as a high severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2011-0717?
To fix CVE-2011-0717, it is recommended to upgrade the Red Hat Network Satellite Server to a patched version provided by Red Hat.
What systems are affected by CVE-2011-0717?
CVE-2011-0717 specifically affects Red Hat Network Satellite Server version 5.4.
What type of attack does CVE-2011-0717 enable?
CVE-2011-0717 enables session fixation attacks that allow an attacker to hijack a user's session.
Can CVE-2011-0717 be exploited remotely?
Yes, CVE-2011-0717 can be exploited remotely if an attacker can set the session cookie in the victim's browser.