You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa pacemaker

Sigurnosni nedostaci programskog paketa pacemaker

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3462-1
October 24, 2017

pacemaker vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Pacemaker.

Software Description:
– pacemaker: Cluster resource manager

Details:

Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handled
the IPC interface. A local attacker could possibly use this issue to
execute arbitrary code with root privileges. (CVE-2016-7035)

Alain Moulle discovered that Pacemaker incorrectly handled authentication.
A remote attacker could possibly use this issue to shut down connections,
leading to a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-7797)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
pacemaker 1.1.14-2ubuntu1.2

Ubuntu 14.04 LTS:
pacemaker 1.1.10+git20130802-1ubuntu2.4

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3462-1
CVE-2016-7035, CVE-2016-7797

Package Information:
https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2
https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJZ70GeAAoJEGVp2FWnRL6TI9EP/AmyKK9Dv4qOGmfSbZktuNWm
EMq9YVCJplABq1UDeW39SnqlXNBVibNyyR7r9pemBDmsAdk46NZy1yA8ZqRxGMC6
fRpnwNWkESbbOnXiQTeiQPm9qVXLUsUeDiAaaQIOKa+Cvjb+xuAt3BNQ5wbLvCce
fs9Hz5//95TOQhoJAZLi6BHqwfH7yogXYn1/+QYz80hScFJGOZRJU+lNQHtgwnCa
uQLYWHP230gpetldK9qbYZIUBmZ1KQnYtvC79rAqwOOlZpxMbMUc1S46hYpF0nqI
c5NRlCpZx3OAzuv/SM2CIMfSe3bQvIfOQTXt73q7onetTGM8pjaKXD18qLvKgzCs
OXuZyXPbfJ/i6ZDtxpbpGWVFuyVddN9vdjsRaWONdUVbbBAXS61XVHqe4D24jv7c
zGXfUJ57NM5q7KG01FOdI7sG2vZbZpcBu2Y5t2U28BfTlfprBxJMov7j148FFY9i
95sIxhEhclNTo3n/3DiQ2jjshOiTEt/+UyeNw+dBHY8KBMcs+uimucxtsm/dphRq
fgcmyvXXQSY6TZBViqY6aIrRHE4318G9PXJmf63bdxDZVBHH2LXZUjmzIyihqK3I
xp4je+ndteESqNk+H1m/Uj1TYmHp3+uMcgoCTO00bAWYcoQ7HMYFu8gnJECpkX7W
Hu5gF+2mDX9xCtTpxYDI
=DIWV
—–END PGP SIGNATURE—–

AutorVlatka Misic
Cert idNCERT-REF-2017-10-0032-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa openvpn

Otkriven je sigurnosni nedostatak u programskom paketu openvpn za operacijski sustav SUSE. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close