RHSA-2011:1794: Moderate: Red Hat Network Satellite server security update

Published Dec 7, 2011
·
Updated

Red Hat Network (RHN) Satellite provides a solution to organizationsrequiring absolute control over and privacy of the maintenance and packagedeployment of their servers. It allows organizations to utilize thebenefits of the Red Hat Network without having to provide public Internetaccess to their servers or other client systems.A cross-site scripting (XSS) flaw was found in the RHN Satellite webinterface. An authenticated RHN Satellite user could use this flaw toperform a cross-site scripting attack against other authenticated users whoare using the RHN Satellite web interface. (CVE-2011-4346)Red Hat would like to thank William Hoffmann for reporting this issue.Users of Red Hat Network Satellite 5.4.1 are advised to upgrade to theseupdated packages, which contain a patch to correct this issue. For thisupdate to take effect, Red Hat Network Satellite must be restarted. Referto the Solution section for details.

Affected Software

16 affected componentsFixes available
redhat/spacewalk-web<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-base<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-base-minimal<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-dobby<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-grail<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-html<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-pxt<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-sniglets<1.2.7-21.el6
1.2.7-21.el6
redhat/spacewalk-web<1.2.7-21.el5
1.2.7-21.el5
redhat/spacewalk-base<1.2.7-21.el5
1.2.7-21.el5
redhat/spacewalk-base-minimal<1.2.7-21.el5
1.2.7-21.el5
redhat/spacewalk-dobby<1.2.7-21.el5
1.2.7-21.el5
redhat/spacewalk-grail<1.2.7-21.el5
1.2.7-21.el5
redhat/spacewalk-html<1.2.7-21.el5
1.2.7-21.el5
redhat/spacewalk-pxt<1.2.7-21.el5
1.2.7-21.el5
redhat/spacewalk-sniglets<1.2.7-21.el5
1.2.7-21.el5

Remediation

Event History

Dec 7, 2011
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2011:1794?

RHSA-2011:1794 is classified as a moderate severity security vulnerability.

2

How do I fix RHSA-2011:1794?

To fix RHSA-2011:1794, you need to upgrade the affected packages to version 1.2.7-21.el6 or 1.2.7-21.el5 as applicable.

3

Which packages are affected by RHSA-2011:1794?

The affected packages for RHSA-2011:1794 include spacewalk-web, spacewalk-base, spacewalk-base-minimal, spacewalk-dobby, spacewalk-grail, spacewalk-html, spacewalk-pxt, and spacewalk-sniglets.

4

What systems are impacted by RHSA-2011:1794?

RHSA-2011:1794 impacts systems running Red Hat Enterprise Linux versions 5 and 6 that utilize the vulnerable Spacewalk packages.

5

Is there a workaround for RHSA-2011:1794?

No official workaround is provided for RHSA-2011:1794; upgrading to the patched versions is the recommended resolution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203