Title : Redhat Security Update Fixes yum-rhn-plugin Security Bypass Issue VUPEN ID : VUPEN/ADV-2008-2388 CVE ID : CVE-2008-3270
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-18
Technical Description
A vulnerability has been identified in various Redhat products, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error in yum-rhn-plugin that does not verify the SSL certificate for all communication with a Red Hat Network server, which could be exploited by attackers to provide malicious repository metadata and block a vulnerable system from receiving specific security updates.