Release date: Affected Systems: RedHatLinux5.0 Description: supplied BUGTRAQID: 40492 CVEID: Provided by the CVE-2010-1439RedHat Operating System
Release date: 2010-06-01
Updated on: 2010-06-02
Affected Systems:
RedHat in Linux 5.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 40492
Cve id: CVE-2010-1439
The Client Tools provided in Red Hat allows the system to receive software upgrades through the Red Hat Network.
Rhn-client-tools: loginAuth used to store session creden. authenticated to the Red Hat Network Server. the pkl file is configured with insecure permissions. You can use these creden to download software packages from the Red Hat Network, and manipulate the software packages or operation lists related to the system configuration file.
<* Source: Red Hat
Link: https://www.redhat.com/support/errata/RHSA-2010-0449.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
For this reason, RedHat has released a Security Bulletin (RHSA-2010: 0449-01) and patch:
RHSA-2010: 0449-01: Moderate: rhn-client-tools security update
Link: https://www.redhat.com/support/errata/RHSA-2010-0449.html