[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2014-1004 -- Oracle yum-updatesd

ID: oval:org.secpod.oval:def:1500671Date: (C)2014-08-11   (M)2023-12-07
Class: PATCHFamily: unix




An updated yum-updatesd package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having Important security impact. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available from the CVE link in the References section. The yum-updatesd package provides a daemon which checks for available updates and can notify you when they are available via email, syslog, or dbus. It was discovered that yum-updatesd did not properly perform RPM package signature checks. When yum-updatesd was configured to automatically install updates, a remote attacker could use this flaw to install a malicious update on the target system using an unsigned RPM or an RPM signed with an untrusted key. All yum-updatesd users are advised to upgrade to this updated package, which contains a backported patch to correct this issue. After installing this update, the yum-updatesd service will be restarted automatically.

Platform:
Oracle Linux 5
Product:
yum-updatesd
Reference:
ELSA-2014-1004
CVE-2014-0022
CVE    1
CVE-2014-0022
CPE    2
cpe:/a:baseurl:yum-updatesd
cpe:/o:oracle:linux:5

© SecPod Technologies