LWN.net Logo

yum-rhn-plugin: SSL certificate not verified

Package(s):yum-rhn-plugin CVE #(s):CVE-2008-3270
Created:August 14, 2008 Updated:August 20, 2008
Description: From the Red Hat alert: It was discovered that yum-rhn-plugin did not verify the SSL certificate for all communication with a Red Hat Network server. An attacker able to redirect the network communication between a victim and an RHN server could use this flaw to provide malicious repository metadata. This metadata could be used to block the victim from receiving specific security updates.
Alerts:
Red Hat RHSA-2008:0815-01 2008-08-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds