First published: Thu Feb 27 2014(Updated: )
The Red Hat Support plug-in for Red Hat Enterprise Virtualization is a new<br>feature which offers seamless integrated access to Red Hat Access services<br>from the Red Hat Enterprise Virtualization Administration Portal. The<br>plug-in provides automated functionality that enables quicker help,<br>answers, and proactive services. It offers easy and instant access to Red<br>Hat exclusive knowledge, resources, engagement, and diagnostic features.<br>Detailed information about this plug-in can be found in the Red Hat<br>Customer Portal at <a href="https://access.redhat.com/site/articles/425603" target="_blank">https://access.redhat.com/site/articles/425603</a> The Jakarta Commons HttpClient component did not verify that the server<br>hostname matched the domain name in the subject's Common Name (CN) or<br>subjectAltName field in X.509 certificates. This could allow a<br>man-in-the-middle attacker to spoof an SSL server if they had a certificate<br>that was valid for any domain name. (CVE-2012-5783)<br>All users of the Red Hat Support plug-in on Red Hat Enterprise<br>Virtualization Manager are advised to install this updated package, which<br>fixes this issue.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/redhat-support-plugin-rhev | <3.3.0-14.el6e | 3.3.0-14.el6e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.