RHSA-2013:0544: Important: Subscription Asset Manager 1.2 update

Published Feb 21, 2013
·
Updated

Red Hat Subscription Asset Manager acts as a proxy for handlingsubscription information and software updates on client machines.It was discovered that Katello did not properly check user permissions whenhandling certain requests. An authenticated remote attacker could use thisflaw to download consumer certificates or change settings of other users'systems if they knew the target system's UUID. (CVE-2012-5603)It was found that the"/usr/share/katello/script/katello-generate-passphrase" utility, which isrun during the installation and configuration process, set world-readablepermissions on the "/etc/katello/secure/passphrase" file. A local attackercould use this flaw to obtain the passphrase for Katello, giving themaccess to information they would otherwise not have access to.(CVE-2012-5561)Note: After installing this update, ensure the"/etc/katello/secure/passphrase" file is owned by the root user and groupand mode 0750 permissions. Sites should also consider re-creating theKatello passphrase as this issue exposed it to local users.Three flaws were found in rubygem-rack. A remote attacker could use theseflaws to perform a denial of service attack against applications usingrubygem-rack. (CVE-2012-6109, CVE-2013-0183, CVE-2013-0184)It was found that rubyparser from rubygem-rubyparser created a temporaryfile in an insecure way. A local attacker could use this flaw to perform asymbolic link attack, overwriting arbitrary files accessible to theapplication using rubyparser. (CVE-2013-0162)The CVE-2012-5603 issue was discovered by Lukas Zapletal of Red Hat;CVE-2012-5561 was discovered by Aaron Weitekamp of the Red Hat CloudQuality Engineering team; and CVE-2013-0162 was discovered by MichaelScherer of the Red Hat Regional IT team.These updated Subscription Asset Manager packages include a number of bugfixes and enhancements. Space precludes documenting all of these changesin this advisory. Refer to the Red Hat Subscription Asset Manager 1.2Release Notes for information about these changes:https://access.redhat.com/knowledge/docs/en-US/RedHatSubscriptionAssetManager/1.2/html/ReleaseNotes/index.html All users of Red Hat Subscription Asset Manager are advised to upgrade tothese updated packages, which fix these issues and add variousenhancements.

Affected Software

54 affected componentsFixes available
redhat/apache-commons-codec<1.7-2.el6_3
1.7-2.el6_3
redhat/apache-mime4j<0.6-4_redhat_1.ep6.el6.1
0.6-4_redhat_1.ep6.el6.1
redhat/candlepin<0.7.23-1.el6_3
0.7.23-1.el6_3
redhat/elasticsearch<0.19.9-5.el6_3
0.19.9-5.el6_3
redhat/katello<1.2.1-15h.el6_3
1.2.1-15h.el6_3
redhat/katello-certs-tools<1.2.1-1h.el6_3
1.2.1-1h.el6_3
redhat/katello-cli<1.2.1-12h.el6_3
1.2.1-12h.el6_3
redhat/katello-configure<1.2.3-3h.el6_3
1.2.3-3h.el6_3
redhat/katello-selinux<1.2.1-2h.el6_3
1.2.1-2h.el6_3
redhat/lucene3<3.6.1-10h.el6_3
3.6.1-10h.el6_3
redhat/puppet<2.6.17-2.el6cf
2.6.17-2.el6cf
redhat/quartz<2.1.5-4.el6_3
2.1.5-4.el6_3
redhat/rubygem-activesupport<3.0.10-10.el6cf
3.0.10-10.el6cf
redhat/rubygem-apipie-rails<0.0.12-2.el6cf
0.0.12-2.el6cf
redhat/rubygem-mail<2.3.0-3.el6cf
2.3.0-3.el6cf
redhat/rubygem-rack<1.3.0-3.el6cf
1.3.0-3.el6cf
redhat/sigar<1.6.5-0.12.git58097d9h.el6_3
1.6.5-0.12.git58097d9h.el6_3
redhat/snappy-java<1.0.4-2.el6_3
1.0.4-2.el6_3
redhat/thumbslug<0.0.28-1.el6_3
0.0.28-1.el6_3
redhat/apache-commons-codec<1.7-2.el6_3
1.7-2.el6_3
redhat/apache-commons-codec-debuginfo<1.7-2.el6_3
1.7-2.el6_3
redhat/apache-mime4j<0.6-4_redhat_1.ep6.el6.1
0.6-4_redhat_1.ep6.el6.1
redhat/apache-mime4j-javadoc<0.6-4_redhat_1.ep6.el6.1
0.6-4_redhat_1.ep6.el6.1
redhat/candlepin<0.7.23-1.el6_3
0.7.23-1.el6_3
redhat/candlepin-devel<0.7.23-1.el6_3
0.7.23-1.el6_3
redhat/candlepin-selinux<0.7.23-1.el6_3
0.7.23-1.el6_3
redhat/candlepin-tomcat6<0.7.23-1.el6_3
0.7.23-1.el6_3
redhat/elasticsearch<0.19.9-5.el6_3
0.19.9-5.el6_3
redhat/katello-certs-tools<1.2.1-1h.el6_3
1.2.1-1h.el6_3
redhat/katello-cli<1.2.1-12h.el6_3
1.2.1-12h.el6_3
redhat/katello-cli-common<1.2.1-12h.el6_3
1.2.1-12h.el6_3
redhat/katello-common<1.2.1-15h.el6_3
1.2.1-15h.el6_3
redhat/katello-configure<1.2.3-3h.el6_3
1.2.3-3h.el6_3
redhat/katello-glue-candlepin<1.2.1-15h.el6_3
1.2.1-15h.el6_3
redhat/katello-headpin<1.2.1-15h.el6_3
1.2.1-15h.el6_3
redhat/katello-headpin-all<1.2.1-15h.el6_3
1.2.1-15h.el6_3
redhat/katello-selinux<1.2.1-2h.el6_3
1.2.1-2h.el6_3
redhat/lucene3<3.6.1-10h.el6_3
3.6.1-10h.el6_3
redhat/lucene3-contrib<3.6.1-10h.el6_3
3.6.1-10h.el6_3
redhat/puppet<2.6.17-2.el6cf
2.6.17-2.el6cf
redhat/puppet-server<2.6.17-2.el6cf
2.6.17-2.el6cf
redhat/quartz<2.1.5-4.el6_3
2.1.5-4.el6_3
redhat/rubygem-activesupport<3.0.10-10.el6cf
3.0.10-10.el6cf
redhat/rubygem-apipie-rails<0.0.12-2.el6cf
0.0.12-2.el6cf
redhat/rubygem-mail<2.3.0-3.el6cf
2.3.0-3.el6cf
redhat/rubygem-mail-doc<2.3.0-3.el6cf
2.3.0-3.el6cf
redhat/rubygem-rack<1.3.0-3.el6cf
1.3.0-3.el6cf
redhat/sigar<1.6.5-0.12.git58097d9h.el6_3
1.6.5-0.12.git58097d9h.el6_3
redhat/sigar-debuginfo<1.6.5-0.12.git58097d9h.el6_3
1.6.5-0.12.git58097d9h.el6_3
redhat/sigar-java<1.6.5-0.12.git58097d9h.el6_3
1.6.5-0.12.git58097d9h.el6_3
redhat/snappy-java<1.0.4-2.el6_3
1.0.4-2.el6_3
redhat/snappy-java-debuginfo<1.0.4-2.el6_3
1.0.4-2.el6_3
redhat/thumbslug<0.0.28-1.el6_3
0.0.28-1.el6_3
redhat/thumbslug-selinux<0.0.28-1.el6_3
0.0.28-1.el6_3

Remediation

Event History

Feb 21, 2013
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2013:0544?

The severity of RHSA-2013:0544 is classified as moderate due to insufficient user permissions checks.

2

How do I fix RHSA-2013:0544?

To fix RHSA-2013:0544, update the affected packages to the recommended versions specified in the advisory.

3

What software is affected by RHSA-2013:0544?

RHSA-2013:0544 affects multiple packages including katello, candlepin, and elasticsearch among others.

4

Can RHSA-2013:0544 be exploited remotely?

Yes, an authenticated remote attacker can exploit RHSA-2013:0544 due to improper user permission checks.

5

Is the vulnerability in RHSA-2013:0544 fixed in later releases?

Yes, the issues addressed in RHSA-2013:0544 are fixed in the later specified versions of the affected packages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203