Red Hat Client Tools 'loginAuth.pkl' Local Security Bypass Vulnerability
BID:40492
Info
Red Hat Client Tools 'loginAuth.pkl' Local Security Bypass Vulnerability
| Bugtraq ID: | 40492 |
| Class: | Design Error |
| CVE: |
CVE-2010-1439 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 01 2010 12:00AM |
| Updated: | Jul 06 2010 10:27PM |
| Credit: | Red Hat |
| Vulnerable: |
Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Redhat Client Tools 0 Avaya IQ 5 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 5.2 |
| Not Vulnerable: | |
Discussion
Red Hat Client Tools 'loginAuth.pkl' Local Security Bypass Vulnerability
Red Hat Client Tools ('rhn-client-tools') is prone to a local security-bypass vulnerability.
A local unauthorized attacker could exploit this issue to gain access to information that will allow them to download packages from the Red Hat Network or manipulate package lists; this may aid in further attacks.
Red Hat Client Tools ('rhn-client-tools') is prone to a local security-bypass vulnerability.
A local unauthorized attacker could exploit this issue to gain access to information that will allow them to download packages from the Red Hat Network or manipulate package lists; this may aid in further attacks.
Exploit / POC
Red Hat Client Tools 'loginAuth.pkl' Local Security Bypass Vulnerability
An attacker can exploit this issue to by using readily available command line tools.
An attacker can exploit this issue to by using readily available command line tools.
Solution / Fix
Red Hat Client Tools 'loginAuth.pkl' Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Red Hat Client Tools 'loginAuth.pkl' Local Security Bypass Vulnerability
References:
References: