Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Fedora 21: 2015-8788 Critical Advisory for pcs Session Security

fedora
Calendar Grey June 4, 2015
Dist Fedora Esm H88
Fedora 21's security update addresses session signing vulnerabilities, bolstering defenses against unauthorized access to sensitive information and user sessions
Fix for CVE-2015-1848, CVE-2015-3983 (sessions not signed)

Summary

pcs is a corosync and pacemaker configuration tool. It permits users to

easily view, modify and created pacemaker based clusters.

Update Information:

Fix for CVE-2015-1848, CVE-2015-3983 (sessions not signed)

Change Log

* Fri May 22 2015 Tomas Jelinek - 0.9.137-4 - Fix for CVE-2015-1848, CVE-2015-3983 (sessions not signed) * Fri Mar 27 2015 Tomas Jelinek - 0.9.137-3 - Fixed postinstall, preuninstall and postuinstall scripts (rhbz#1096224) * Wed Dec 17 2014 Chris Feist - 0.9.137-2 - Bind to 0.0.0.0 instead of ipv6 address by default * Tue Dec 16 2014 Chris Feist - 0.9.137-1 - Re-synced to upstream sources

References


[ 1 ] Bug #1208294 - CVE-2015-1848 CVE-2015-3983 pcs: improper web session variable signing https://bugzilla.redhat.com/show_bug.cgi?id=1208294

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pcs' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pcs
Product: Fedora 21
Version: 0.9.137
Release: 4.fc21
Summary: Pacemaker Configuration System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here