==========================================================================
Ubuntu Security Notice USN-4000-1
May 30, 2019
corosync vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
Summary:
Corosync could be made to crash or execute arbitrary code if it
received a specially crafted request.
Software Description:
– corosync: cluster engine daemon and utilities
Details:
It was discovered that Corosync incorrectly handled certain requests.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
corosync 2.4.3-0ubuntu1.1
libtotem-pg5 2.4.3-0ubuntu1.1
Ubuntu 16.04 LTS:
corosync 2.3.5-3ubuntu2.3
libtotem-pg5 2.3.5-3ubuntu2.3
After a standard system update you need to restart Corosync to make
all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-4000-1
CVE-2018-1084
Package Information:
https://launchpad.net/ubuntu/+source/corosync/2.4.3-0ubuntu1.1
https://launchpad.net/ubuntu/+source/corosync/2.3.5-3ubuntu2.3—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2
iQIcBAABCAAGBQJc8BIVAAoJEEW851uECx9pRRYP/1eYrlaCZDsi8+hNp0cpDaDI
V1F3klH5qcEQa9rrgdQFflib1l/vbMmwwQTKnYKso30MTXceN6qKwAuoZ5x6UzTI
R/RXxicuHkPGF/KIz6nRMCxWpXgLPssSWNFscN0M10Dup8epvvpKxMs1jiQdyh9f
B2MBN1TDChEUiEaFaphb7UnaJYW/eWkHgzLdiGwg7R3dEoaHyh0aGO+gJ6twm44q
T5LlcofGOuEidcxCa/81BemkxJHrjb9sPEieUunCqv+Efvwr348flnu56lZOeEf7
3Pe325tGZmyLzhX2JcSS/TMklmY2OcbtJruBTF5IJWZ5I5eLORkadqP1b2wDxj/a
H/Os2i6eTyDOhcqWMRSNXVqW2VMs7Tbq0P/nnrqPumLunsP1g1G7h7q6S4wZ5cQ8
csXrO0TFuoTkp9mF2/0+yhmyt156SDB1k76JCu47DhqA3GPJnIcwAURkcVIYPxE6
u9PBEiHZqmcvMdCjfx+R0lh4Pf18ybFtRJtzHcJZ1xvyjCZR6E2hklvDvnvc0hHX
iqbdbz/u3JeB0y4luF4/kc6rCyLMgbPPY/hELSFGZrEdA/TcscKvBBCzP5S+EaEc
UplL8vfcGuHh6iJTbXJa7vvzk98RiZVwphSAM+aNw+em1CEwufIB8qrpw8MeVt41
hoJ9Kiewh13MRGWZoTJq
=VvR3
—–END PGP SIGNATURE—–
—