Release date:
Updated on:
Affected Systems:
RedHat Satellite Server 5.x
RedHat Network Proxy (for RHEL 6) 5.4
RedHat Network Proxy (for RHEL 5) 5.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51569
Cve id: CVE-2012-0059
The Satellite server supports a network-based Authentication system through PAM (Pluggable Authentication Modules.
Multiple RedHat products such as Red Hat Network Satellite Server, Red Hat Network Proxy Server, and Spacewalk have remote information leakage vulnerability in implementation. If the user submits a system registration XML-RPC to call RHN Server, after the call fails, the RHN user password is included in the error message in the server log. After successful exploitation, attackers can obtain user creden.
<* Source: Red Hat
Link: https://rhn.redhat.com/errata/RHSA-2012-0101.html
Https://rhn.redhat.com/errata/RHSA-2012-0102.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.redhat.com/apps/support/errata/index.html