Security Advisory

CVE-2008-3270

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-08-18 17:15:00
Last updated 2024-08-07 09:28:41
Assigner redhat
State PUBLISHED

Description

yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file download from a Red Hat Network (RHN) server, which makes it easier for remote man-in-the-middle attackers to cause a denial of service (loss of updates) or force the download and installation of official Red Hat packages that were not requested.