RHSA-2013:0686: Moderate: Subscription Asset Manager 1.2.1 update

Published Mar 26, 2013
·
Updated

Red Hat Subscription Asset Manager acts as a proxy for handlingsubscription information and software updates on client machines.The latest packages for Subscription Asset Manager include a number of securityfixes:When a Subscription Asset Manager instance is created, its configurationscript automatically creates an RPM of the internal subscription service CA certificate. However, this RPM incorrectly created the CA certificatewith file permissions of 0666. This allowed other users on a client systemto modify the CA certificate used to trust the remote subscription server.All administrators are advised to update and deploy the subscriptionservice certificate on all systems which use Subscription Asset Manageras their subscription service. This procedure is described in:https://access.redhat.com/knowledge/docs/en-US/RedHatSubscriptionAssetManager/1.2/html/InstallationGuide/sect-InstallationGuide-Administration-UpgradingSubscriptionAssetManager.html (CVE-2012-6116)Manifest signature checking was not implemented for early versions of Subscription Asset Manager. This meant that a malicious user could edita manifest file, insert arbitrary data, and successfully upload the editedmanifest file into the Subscription Asset Manager server. (CVE-2012-6119)Ruby's documentation generator had a flaw in the way it generated HTMLdocumentation. When a Ruby application exposed its documentationon a network (such as a web page), an attacker could use a specially-crafted URL to open an arbitrary web script or to execute HTML codewithin the application's user session. (CVE-2013-0256)A timing attack flaw was found in the way rubygem-rack andruby193-rubygem-rack processed HMAC digests in cookies. This flaw could aidan attacker using forged digital signatures to bypass authenticationchecks. (CVE-2013-0263)A flaw in rubygem-json allowed remote attacks by creating different typesof malicious objects. For example, it could initiate a denial of service(DoS) attack through resource consumption by using a JSON document tocreate arbitrary Ruby symbols, which were never garbage collected. Itcould also be exploited to create internal objects which could allow a SQLinjection attack. (CVE-2013-0269)A flaw in ActiveRecord in Ruby on Rails allowed remote attackers tocircumvent attribute protections and to insert their own crafted requeststo change protected attribute values. (CVE-2013-0276)HTML markup was not properly escaped when filling in the username field inthe Notifications form of the Subscription Asset Manager UI. This meantthat HTML code used in the value was then applied in the UI page when theentry was viewed. This could have allowed malicious HTML code to beentered. The field value is now validated and any HTML tags are escaped.(CVE-2013-1823)These updated packages also include bug fixes and enhancements: Previously, no SELinux policy for the subscription service was included with the Subscription Asset Manager packages. The candlepin-selinux packageis now included with SELinux policies for the subscription server. (BZ#906901) When attempting to use the subscription service's CA certificate to validate a manifest during import, the comparison failed. The upstreamsubscription service which generated the manifest is a different servicethan the local subscription service; thus, they have different CAcertificates. This caused importing a manifest to fail with the error'archive failed signature'. This has been fixed so that the propercertificate is used for verification. (BZ#918778)All users of Subscription Asset Manager are recommended to update to thelatest packages.

Affected Software

33 affected componentsFixes available
redhat/candlepin<0.7.24-1.el6_3
0.7.24-1.el6_3
redhat/katello<1.2.1.1-1h.el6_4
1.2.1.1-1h.el6_4
redhat/katello-configure<1.2.3.1-4h.el6_4
1.2.3.1-4h.el6_4
redhat/rubygem-actionpack<3.0.10-12.el6cf
3.0.10-12.el6cf
redhat/rubygem-activemodel<3.0.10-3.el6cf
3.0.10-3.el6cf
redhat/rubygem-json<1.7.3-2.el6_3
1.7.3-2.el6_3
redhat/rubygem-nokogiri<1.5.0-0.9.beta4.el6cf
1.5.0-0.9.beta4.el6cf
redhat/rubygem-rack<1.3.0-4.el6cf
1.3.0-4.el6cf
redhat/rubygem-rdoc<3.8-6.el6cf
3.8-6.el6cf
redhat/thumbslug<0.0.28.1-1.el6_4
0.0.28.1-1.el6_4
redhat/candlepin<0.7.24-1.el6_3
0.7.24-1.el6_3
redhat/candlepin-devel<0.7.24-1.el6_3
0.7.24-1.el6_3
redhat/candlepin-selinux<0.7.24-1.el6_3
0.7.24-1.el6_3
redhat/candlepin-tomcat6<0.7.24-1.el6_3
0.7.24-1.el6_3
redhat/katello-common<1.2.1.1-1h.el6_4
1.2.1.1-1h.el6_4
redhat/katello-configure<1.2.3.1-4h.el6_4
1.2.3.1-4h.el6_4
redhat/katello-glue-candlepin<1.2.1.1-1h.el6_4
1.2.1.1-1h.el6_4
redhat/katello-headpin<1.2.1.1-1h.el6_4
1.2.1.1-1h.el6_4
redhat/katello-headpin-all<1.2.1.1-1h.el6_4
1.2.1.1-1h.el6_4
redhat/ruby-nokogiri<1.5.0-0.9.beta4.el6cf
1.5.0-0.9.beta4.el6cf
redhat/rubygem-actionpack<3.0.10-12.el6cf
3.0.10-12.el6cf
redhat/rubygem-activemodel<3.0.10-3.el6cf
3.0.10-3.el6cf
redhat/rubygem-activemodel-doc<3.0.10-3.el6cf
3.0.10-3.el6cf
redhat/rubygem-json<1.7.3-2.el6_3
1.7.3-2.el6_3
redhat/rubygem-json-debuginfo<1.7.3-2.el6_3
1.7.3-2.el6_3
redhat/rubygem-nokogiri<1.5.0-0.9.beta4.el6cf
1.5.0-0.9.beta4.el6cf
redhat/rubygem-nokogiri-debuginfo<1.5.0-0.9.beta4.el6cf
1.5.0-0.9.beta4.el6cf
redhat/rubygem-nokogiri-doc<1.5.0-0.9.beta4.el6cf
1.5.0-0.9.beta4.el6cf
redhat/rubygem-rack<1.3.0-4.el6cf
1.3.0-4.el6cf
redhat/rubygem-rdoc<3.8-6.el6cf
3.8-6.el6cf
redhat/rubygem-rdoc-doc<3.8-6.el6cf
3.8-6.el6cf
redhat/thumbslug<0.0.28.1-1.el6_4
0.0.28.1-1.el6_4
redhat/thumbslug-selinux<0.0.28.1-1.el6_4
0.0.28.1-1.el6_4

Remediation

Event History

Mar 26, 2013
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2013:0686?

The severity of RHSA-2013:0686 is classified as important.

2

How do I fix RHSA-2013:0686?

To fix RHSA-2013:0686, update the affected packages to the specified versions outlined in the advisory.

3

Which packages are affected by RHSA-2013:0686?

RHSA-2013:0686 affects several packages, including candlepin, katello, and various rubygem libraries.

4

Is RHSA-2013:0686 related to subscription management software?

Yes, RHSA-2013:0686 pertains to vulnerabilities in Red Hat Subscription Asset Manager and related software.

5

What version should I update to for RHSA-2013:0686?

You should update to the latest specified versions for affected packages mentioned in the advisory for RHSA-2013:0686.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203