Vulnerabilities > CVE-2003-0546 - Unspecified vulnerability in Redhat Up2Date 3.0.71/3.1.231

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
redhat

Summary

up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.

Vulnerable Configurations

Part Description Count
Application
Redhat
4

Oval

accepted2007-04-25T19:52:38.112-04:00
classvulnerability
contributors
  • nameJay Beale
    organizationBastille Linux
  • nameJay Beale
    organizationBastille Linux
  • nameThomas R. Jones
    organizationMaitreya Security
descriptionup2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.
familyunix
idoval:org.mitre.oval:def:631
statusaccepted
submitted2003-09-03T12:00:00.000-04:00
titleup2date RPM GPG Signature Verification Vulnerability
version36

Redhat

advisories
rhsa
idRHSA-2003:255