==========================================================================
Ubuntu Security Notice USN-3462-1
October 24, 2017
pacemaker vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Pacemaker.
Software Description:
– pacemaker: Cluster resource manager
Details:
Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handled
the IPC interface. A local attacker could possibly use this issue to
execute arbitrary code with root privileges. (CVE-2016-7035)
Alain Moulle discovered that Pacemaker incorrectly handled authentication.
A remote attacker could possibly use this issue to shut down connections,
leading to a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-7797)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
pacemaker 1.1.14-2ubuntu1.2
Ubuntu 14.04 LTS:
pacemaker 1.1.10+git20130802-1ubuntu2.4
In general, a standard system update will make all the necessary changes.
References:
https://www.ubuntu.com/usn/usn-3462-1
CVE-2016-7035, CVE-2016-7797
Package Information:
https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2
https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2
iQIcBAEBCgAGBQJZ70GeAAoJEGVp2FWnRL6TI9EP/AmyKK9Dv4qOGmfSbZktuNWm
EMq9YVCJplABq1UDeW39SnqlXNBVibNyyR7r9pemBDmsAdk46NZy1yA8ZqRxGMC6
fRpnwNWkESbbOnXiQTeiQPm9qVXLUsUeDiAaaQIOKa+Cvjb+xuAt3BNQ5wbLvCce
fs9Hz5//95TOQhoJAZLi6BHqwfH7yogXYn1/+QYz80hScFJGOZRJU+lNQHtgwnCa
uQLYWHP230gpetldK9qbYZIUBmZ1KQnYtvC79rAqwOOlZpxMbMUc1S46hYpF0nqI
c5NRlCpZx3OAzuv/SM2CIMfSe3bQvIfOQTXt73q7onetTGM8pjaKXD18qLvKgzCs
OXuZyXPbfJ/i6ZDtxpbpGWVFuyVddN9vdjsRaWONdUVbbBAXS61XVHqe4D24jv7c
zGXfUJ57NM5q7KG01FOdI7sG2vZbZpcBu2Y5t2U28BfTlfprBxJMov7j148FFY9i
95sIxhEhclNTo3n/3DiQ2jjshOiTEt/+UyeNw+dBHY8KBMcs+uimucxtsm/dphRq
fgcmyvXXQSY6TZBViqY6aIrRHE4318G9PXJmf63bdxDZVBHH2LXZUjmzIyihqK3I
xp4je+ndteESqNk+H1m/Uj1TYmHp3+uMcgoCTO00bAWYcoQ7HMYFu8gnJECpkX7W
Hu5gF+2mDX9xCtTpxYDI
=DIWV
—–END PGP SIGNATURE—–
—