DetailsRed Hat Network Satellite Server version 5.0.2 is now available. This
During an internal security review, a cross-site scripting flaw was found SolutionThis update is available via Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at http://www.redhat.com/docs/manuals/satellite/Red_Hat_Network_Satellite-5.0.0/html/Installation_Guide/s1-maintenance-update.html Updated packages
Bugs fixed (see bugzilla for more information)396641 - CVE-2007-5961 RHN XSS flaw References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0885
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0605 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2090 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3510 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3964 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4838 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0254 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0898 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1329 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3835 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5752 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7195 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7196 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7197 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0243 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0450 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1349 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1355 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1358 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1860 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2435 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2449 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2450 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2788 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2789 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3382 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4465 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5000 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5461 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5961 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6306 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6388 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0128 http://www.redhat.com/security/updates/classification/#moderate These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from: https://www.redhat.com/security/team/key/#package The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/ |
||||||||||||||||||||||||||||||||||||||||||||||||||