MEDIUM
openstack-heat-templates: setting gpgcheck=0 for signed packages
Published Jun 2, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.47%
Description
OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets gpgcheck to 0 for certain templates, which disables GPG signature checking on downloaded packages and allows man-in-the-middle attackers to install arbitrary packages via unspecified vectors.
Affected products
No data.
No data.
OpenStack 4 for RHEL 6
openstack-heat-templates-0:0-0.3.20140407git.el6ost
Fixed · RHSA-2014:0579
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 4 for RHEL 6 | openstack-heat-templates-0:0-0.3.20140407git.el6ost | Fixed | RHSA-2014:0579 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://rhn.redhat.com/errata/RHSA-2014-0579.html vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2014-0042 Vendor Advisory
- https://bugs.launchpad.net/heat-templates/+bug/1267635 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=1059520 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0139 Advisory
- https://github.com/openstack/heat-templates/commit/65a4f8bebc72da71c616e2e378b7b1ac354db1a3 x_refsource_CONFIRMExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2014-0042
- https://www.cve.org/CVERecord?id=CVE-2014-0042
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2014-0579.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2014-0042 | Vendor Advisory | |
| https://bugs.launchpad.net/heat-templates/+bug/1267635 | x_refsource_MISC | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1059520 | x_refsource_CONFIRMIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0139 | Advisory | |
| https://github.com/openstack/heat-templates/commit/65a4f8bebc72da71c616e2e378b7b1ac354db1a3 | x_refsource_CONFIRMExploitPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-0042 | ||
| https://www.cve.org/CVERecord?id=CVE-2014-0042 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 2, 2014
Updated Aug 6, 2024
Reserved Dec 3, 2013
Link CVE-2014-0042
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2014-0139 Assigner redhat
Published Jun 2, 2014
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2014-0139