fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/06/12/8 | mailing list third party advisory patch |
https://lists.fedoraproject.org/archives/list/spins%40lists.fedoraproject.org/thread/L3GSGM5JS2EAJJAGEHR7U4ATNM4ILFKK/ | mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1231800 | issue tracking third party advisory patch |
http://www.securityfocus.com/bid/75185 | vdb entry third party advisory |