Lucene search

K
redhatRedHatRHSA-2012:0102
HistoryFeb 06, 2012 - 12:00 a.m.

(RHSA-2012:0102) Low: Red Hat Network Proxy spacewalk-backend security and bug fix update

2012-02-0600:00:00
access.redhat.com
16

EPSS

0.001

Percentile

50.4%

Red Hat Network (RHN) Proxy provides a mechanism for caching content, such
as package updates from Red Hat or custom content created for an
organization on an internal, centrally-located server.

If a user submitted a system registration XML-RPC call to an RHN Proxy
server (for example, by running “rhnreg_ks”) and that call failed, their
RHN user password was included in plain text in the error messages both
stored in the server log and mailed to the server administrator. With this
update, user passwords are excluded from these error messages to avoid the
exposure of authentication credentials. (CVE-2012-0059)

Users of Red Hat Network Proxy are advised to upgrade to these updated
packages, which correct this issue. For this update to take effect,
Red Hat Network Proxy must be restarted. Refer to the Solution section for
details.

EPSS

0.001

Percentile

50.4%