CVE-2014-3585: Critical severity red hat upgrade tool vulnerability
Published Nov 22, 2019
·Updated
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
Affected Software
3 affected components
redhat redhat-upgrade-tool
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
Event History
Nov 22, 2019
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2014-3585?
CVE-2014-3585 has been assigned a medium severity rating due to the lack of GPG signature verification during upgrades.
2
How do I fix CVE-2014-3585?
To fix CVE-2014-3585, ensure that you manually verify the integrity of software updates before installing them.
3
What software is affected by CVE-2014-3585?
CVE-2014-3585 affects the redhat-upgrade-tool across Red Hat Enterprise Linux 6.0 and 7.0 versions.
4
What are the risks associated with CVE-2014-3585?
The risks of CVE-2014-3585 include potential installation of unauthorized or tampered packages due to the lack of signature verification.
5
Is there a patch available for CVE-2014-3585?
Red Hat has provided updates for the redhat-upgrade-tool that address the vulnerabilities associated with CVE-2014-3585.