PureApplication -Why do I need to update yum-rhn-plugin and spacewalk-backend before the httpd errata is released with Satellite RHEL v5?

A yum-rhn-plugin fix in 2016 contained a bug involving whitespace between headers in HTTP requests between a Satellite or Proxy 5 server and its clients. When the fix for Bug 1412974 CVE-2016-8743 is released and applied, httpd strictly enforces white space constraints on incoming HTTP requests, rejecting requests coming from such clients. In order to avoid breaking yum communication between a Satellite instance and its clients, both Server and Client-side fixes are needed which involves applying errata [1] as well as additional steps *in order*.


Leave a Reply