yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file download from a Red Hat Network (RHN) server, which makes it easier for remote man-in-the-middle attackers to cause a denial of service (loss of updates) or force the download and installation of official Red Hat packages that were not requested.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2008-0815.html | vendor advisory |
http://secunia.com/advisories/31472 | third party advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10864 | vdb entry signature |
http://securitytracker.com/id?1020698 | vdb entry |
http://www.securityfocus.com/bid/30695 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=457113 |