CVE Vulnerabilities

CVE-2010-1171

Published: Apr 18, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:P
RedHat/V2
5.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:N/A:P
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.

Affected Software

NameVendorStart VersionEnd Version
SatelliteRedhat5.3 (including)5.3 (including)
SatelliteRedhat5.4 (including)5.4 (including)
Red Hat Network Satellite Server v 5.3RedHatspacewalk-backend-0:0.5.28-59.2.el5sat*
Red Hat Network Satellite Server v 5.3RedHatspacewalk-config-0:0.5.9-16.el5sat*
Red Hat Network Satellite Server v 5.4RedHatspacewalk-backend-0:1.2.13-37.el5sat*
Red Hat Network Satellite Server v 5.4RedHatspacewalk-config-0:1.2.2-2.el5sat*

References