3.6
CVE-2010-1439
- EPSS 0.04%
- Published 07.06.2010 17:12:48
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.
Data is provided by the National Vulnerability Database (NVD)
Redhat ≫ Yum-rhn-plugin
Redhat ≫ Rhn-client-tools
Fedoraproject ≫ Fedora
Redhat ≫ Enterprise Linux Version5
Redhat ≫ Enterprise Linux Version5 Updatega Editionserver
Redhat ≫ Enterprise Linux Version5.0
Fedoraproject ≫ Fedora
Redhat ≫ Enterprise Linux Version5
Redhat ≫ Enterprise Linux Version5 Updatega Editionserver
Redhat ≫ Enterprise Linux Version5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.132 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:P/I:P/A:N
|