Oval Definition:oval:org.mitre.oval:def:9232
Revision Date:2013-04-29Version:12
Title:yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.
Description:yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-1439
Platform(s):CentOS Linux 5
Oracle Linux 5
Red Hat Enterprise Linux 5
Product(s):
Definition Synopsis
  • RHEL5, CentOS5 or Oracle Linux 5
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • OR Oracle Linux 5.x
  • AND Configuration section
  • rhn-check is earlier than 0:0.4.20-33.el5_5.2
  • OR rhn-setup is earlier than 0:0.4.20-33.el5_5.2
  • OR rhn-client-tools is earlier than 0:0.4.20-33.el5_5.2
  • OR rhn-setup-gnome is earlier than 0:0.4.20-33.el5_5.2
  • BACK