[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2016:2592-02 -- Redhat python-rhsm, subscription-manager, subscription-manager-migration-data

ID: oval:org.secpod.oval:def:501919Date: (C)2016-11-07   (M)2023-02-20
Class: PATCHFamily: unix




The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the Red Hat entitlement platform. The subscription-manager-migration-data package provides certificates for migrating a system from the legacy Red Hat Network Classic to Red Hat Subscription Management . The python-rhsm packages provide a library for communicating with the representational state transfer interface of a Red Hat Unified Entitlement Platform. The Subscription Management tools use this interface to manage system entitlements, certificates, and access to content. The following packages have been upgraded to a newer upstream version: subscription-manager , python-rhsm , subscription-manager-migration-data . Security Fix: * It was found that subscription-manager set weak permissions on files in /var/lib/rhsm/, causing an information disclosure. A local, unprivileged user could use this flaw to access sensitive data that could potentially be used in a social engineering attack. Red Hat would like to thank Robert Scheck for reporting this issue. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 7
Product:
python-rhsm
subscription-manager
Reference:
RHSA-2016:2592-02
CVE-2016-4455
CVE    1
CVE-2016-4455
CPE    3
cpe:/o:redhat:enterprise_linux:7
cpe:/a:epractizelabs:subscription-manager
cpe:/a:fedorahosted:python-rhsm

© SecPod Technologies