CVE-2012-1145
published 2012-06-16CVE-2012-1145: spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.02%
85.9th percentile
spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
satellite: remote package upload without authorization
vendor_redhat·2012-03-29·CVSS 5.0
CVE-2012-1145 [MEDIUM] satellite: remote package upload without authorization
satellite: remote package upload without authorization
spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads.
Statement: This vulnerability only applies to RHN Satellite 5.4 when running on Red Hat Enterprise Linux 6 under mod_wsgi. As the code uses mod_python when performing these checks on Red Hat Enterprise Linux 5, that version is not vulnerable to this flaw.
GHSA
GHSA-c32r-w7r9-9w44: spacewalk-backend in Red Hat Network Satellite 5
ghsa_unreviewed·2022-05-13
CVE-2012-1145 [MEDIUM] CWE-287 GHSA-c32r-w7r9-9w44: spacewalk-backend in Red Hat Network Satellite 5
spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1145 satellite: remote package upload without authorization [fedora-18]
bugzilla·2012-03-29·CVSS 5.0
CVE-2012-1145 [MEDIUM] CVE-2012-1145 satellite: remote package upload without authorization [fedora-18]
CVE-2012-1145 satellite: remote package upload without authorization [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
Bugzilla
CVE-2012-1145 satellite: remote package upload without authorization
bugzilla·2012-03-06·CVSS 5.0
CVE-2012-1145 [MEDIUM] CVE-2012-1145 satellite: remote package upload without authorization
CVE-2012-1145 satellite: remote package upload without authorization
It was discovered that a remote attacker was able to upload a package to a Spacewalk/Satellite NULL organization without any authorization or authentication. A NULL organization is one to which packages synced from Red Hat Network Hosted land. Although an attacker is not able to put packages into an arbitrary channel, he could upload several packages and fill up the /var partition with such files. While these packages are not copied to legitimate channels and would not be downloaded by client systems, a full partition would prevent the downloading of new legitimate packages, which may include security fixes. These packages would then be unavailable to client systems.
Discussion:
Statement:
This vulnerability only appl
http://rhn.redhat.com/errata/RHSA-2012-0436.htmlhttp://secunia.com/advisories/48664http://www.osvdb.org/81481http://www.securityfocus.com/bid/52832http://www.securitytracker.com/id?1026873https://exchange.xforce.ibmcloud.com/vulnerabilities/74498http://rhn.redhat.com/errata/RHSA-2012-0436.htmlhttp://secunia.com/advisories/48664http://www.osvdb.org/81481http://www.securityfocus.com/bid/52832http://www.securitytracker.com/id?1026873https://exchange.xforce.ibmcloud.com/vulnerabilities/74498
2012-06-16
Published