« Volver al listado

CVE-2010-1439

Estado: ModificadaBaja (3.6)—

yum-rhn-plugin en Red Hat Network Client Tools (también conocido como rhn-client-tools) en Red Hat Enterprise Linux (RHEL) v5 y Fedora utiliza permisos de lectura para todo el mundo (world-readable) para el archivo /var/spool/up2date/loginAuth.pkl, lo que permite a usuarios locales acceder al perfil Red Hat Network, y posiblemente prevenir futuras actualizaciones de seguridad, aprovechando los datos de autenticación de este archivo.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-1439",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-06-07T17:12:48.077",
  "references": [
    {
      "url": "http://secunia.com/advisories/39996",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://securitytracker.com/id?1024049",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.osvdb.org/65063",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2010-0449.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/40492",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1311",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=585386",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/59114",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9232",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/39996",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1024049",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/65063",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2010-0449.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/40492",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1311",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=585386",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/59114",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9232",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file."
    },
    {
      "lang": "es",
      "value": "yum-rhn-plugin en Red Hat Network Client Tools (también conocido como rhn-client-tools) en Red Hat Enterprise Linux (RHEL) v5 y Fedora utiliza permisos de lectura para todo el mundo (world-readable) para el archivo /var/spool/up2date/loginAuth.pkl, lo que permite a usuarios locales acceder al perfil Red Hat Network, y posiblemente prevenir futuras actualizaciones de seguridad, aprovechando los datos de autenticación de este archivo."
    }
  ],
  "lastModified": "2026-06-16T23:18:23.680",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:rhn-client-tools:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4A06CC31-3043-4C6D-B34B-F1C46128D6F7"
            },
            {
              "criteria": "cpe:2.3:a:redhat:yum-rhn-plugin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3FC7890-5ADB-48E7-A2DE-6A4507D326CA"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "20294CE7-12C8-43CA-A702-5ED2A3044FFC"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AA9B3CC0-DF1C-4A86-B2A3-A9D428A5A6E6"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:ga:server:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E2B82497-CA71-486C-8632-ABF597CA40F0"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1D8B549B-E57B-4DFE-8A13-CAB06B5356B3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}