Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Fedora 21 FEDORA-2015-5872 Critical: Netcf CVE-2014-8119 Fix

fedora
Calendar Grey May 11, 2015
Dist Fedora Esm H88
Patch implemented for netcf addressing CVE 2014-8119 with improvements for Fedora 21. Upgrade your systems promptly.
Security fix for CVE 2014-8119, as well as adding a few other minor bugfixes and enhancements (support for multiple IPv4 addresses, simultaneous static & dhcp for IPv4)

Summary

Netcf is a library used to modify the network configuration of a

system. Network configurations are expressed in a platform-independent

XML format, which netcf translates into changes to the system's

'native' network configuration files.

Update Information:

Security fix for CVE 2014-8119, as well as adding a few other minor bugfixes and enhancements (support for multiple IPv4 addresses, simultaneous static & dhcp for IPv4)

Change Log

* Wed Apr 8 2015 Laine Stump - 0.2.8-1 - rebase to netcf-0.2.8 - resolve CVE-2014-8119 - Fix build on systems with newer libnl3 that doesn't - support multiple IPv4 addresses in interface config (redhat driver) - allow static IPv4 config simultaneous with DHCPv4 (redhat driver) - recognize IPADDR0/NETMASK0/PREFIX0 - remove extra quotes from IPV6ADDR_SECONDARIES (redhat+suse drivers) - miscellaneous systemd service fixes - use git to apply patches in rpm specfile - revert the 0.2.6-2 specfile patch mentioned below (now fixed properly) * Thu Jan 8 2015 Zbigniew Jędrzejewski-Szmek - 0.2.6-2 - do not write to the console (#1135744)

References


[ 1 ] Bug #1172176 - CVE-2014-8119 netcf: augeas path expression injection via interface name https://bugzilla.redhat.com/show_bug.cgi?id=1172176

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update netcf' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: netcf
Product: Fedora 21
Version: 0.2.8
Release: 1.fc21
Summary: Cross-platform network configuration library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here