Executive Summary

Informations
Name CVE-2008-3270 First vendor Publication 2008-08-18
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:N/I:P/A:N)
Cvss Base Score 2.6 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity High
Cvss Expoit Score 4.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file download from a Red Hat Network (RHN) server, which makes it easier for remote man-in-the-middle attackers to cause a denial of service (loss of updates) or force the download and installation of official Red Hat packages that were not requested.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3270

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-310 Cryptographic Issues

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:10864
 
Oval ID: oval:org.mitre.oval:def:10864
Title: yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file download from a Red Hat Network (RHN) server, which makes it easier for remote man-in-the-middle attackers to cause a denial of service (loss of updates) or force the download and installation of official Red Hat packages that were not requested.
Description: yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file download from a Red Hat Network (RHN) server, which makes it easier for remote man-in-the-middle attackers to cause a denial of service (loss of updates) or force the download and installation of official Red Hat packages that were not requested.
Family: unix Class: vulnerability
Reference(s): CVE-2008-3270
Version: 5
Platform(s): Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21730
 
Oval ID: oval:org.mitre.oval:def:21730
Title: ELSA-2008:0815: yum-rhn-plugin security update (Moderate)
Description: yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file download from a Red Hat Network (RHN) server, which makes it easier for remote man-in-the-middle attackers to cause a denial of service (loss of updates) or force the download and installation of official Red Hat packages that were not requested.
Family: unix Class: patch
Reference(s): ELSA-2008:0815-02
CVE-2008-3270
Version: 6
Platform(s): Oracle Linux 5
Product(s): yum-rhn-plugin
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:28842
 
Oval ID: oval:org.mitre.oval:def:28842
Title: RHSA-2008:0815 -- yum-rhn-plugin security update (Moderate)
Description: Updated yum-rhn-plugin packages that fix a security issue are now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. The yum-rhn-plugin provides support for yum to securely access a Red Hat Network (RHN) server for software updates.
Family: unix Class: patch
Reference(s): RHSA-2008:0815
CVE-2008-3270
Version: 3
Platform(s): Red Hat Enterprise Linux 5
Product(s): yum-rhn-plugin
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 1

OpenVAS Exploits

Date Description
2009-03-06 Name : RedHat Update for yum-rhn-plugin RHSA-2008:0815-01
File : nvt/gb_RHSA-2008_0815-01_yum-rhn-plugin.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
47661 Red Hat Enterprise Linux yum-rhn-plugin SSL Certificate Verification Failure ...

Nessus® Vulnerability Scanner

Date Description
2012-08-01 Name : The remote Scientific Linux host is missing a security update.
File : sl_20080814_yum_rhn_plugin_on_SL5_x.nasl - Type : ACT_GATHER_INFO
2008-08-15 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2008-0815.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

http://secunia.com/advisories/31472
http://securitytracker.com/id?1020698
http://www.redhat.com/support/errata/RHSA-2008-0815.html
http://www.securityfocus.com/bid/30695
https://bugzilla.redhat.com/show_bug.cgi?id=457113
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2024-11-28 23:13:41
  • Multiple Updates
2024-11-28 12:16:06
  • Multiple Updates
2021-05-04 12:07:49
  • Multiple Updates
2021-04-22 01:08:12
  • Multiple Updates
2020-05-23 00:22:00
  • Multiple Updates
2017-09-29 09:23:38
  • Multiple Updates
2016-04-26 17:39:32
  • Multiple Updates
2014-02-17 10:45:48
  • Multiple Updates
2013-05-11 00:22:02
  • Multiple Updates