Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 21 FEDORA-2015-8919 Critical: Thermostat Credential Leak

fedora
Calendar Grey June 10, 2015
Dist Fedora Esm H88
Urgent patch released for Fedora 21's Thermostat application resolves sensitive data exposure concerns swiftly.
Security fix for CVE-2015-3201

Summary

Thermostat is a monitoring and instrumentation tool for the Hotspot JVM,

with support for monitoring multiple JVM instances. The system is made

up of two processes: an Agent, which collects data, and a Client which

allows users to visualize this data. These components communicate via

a MongoDB-based storage layer. A pluggable agent and gui framework

allows for collection and visualization of performance data beyond that

which is included out of the box.

Update Information:

Security fix for CVE-2015-3201

Change Log

* Thu May 21 2015 Severin Gehwolf - 1.0.6-2 - Make web.xml no longer word-readable. - Resolves: CVE-2015-3201 * Thu Dec 18 2014 Elliott Baron - 1.0.6-1 - Update to latest maintenance release. - Resolves: CVE-2014-8120 * Mon Oct 13 2014 Severin Gehwolf - 1.0.4-4.5 - Use /etc/alternatives/java_sdk_openjdk as jdk_base. * Mon Oct 13 2014 Severin Gehwolf - 1.0.4-4.4 - Remove obsolete requires on gnome-icon-theme.

References


[ 1 ] Bug #1221989 - CVE-2015-3201 thermostat: world-readable configuration file containing credentials https://bugzilla.redhat.com/show_bug.cgi?id=1221989

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update thermostat' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: thermostat
Product: Fedora 21
Version: 1.0.6
Release: 2.fc21
URL: Summary : A monitoring and serviceability tool for OpenJDK

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here