Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 23 pcs Security Advisory: Cross-Site Request Forgery Fix

fedora
Calendar Grey March 3, 2016
Dist Fedora Esm H88
Critical Alert for Fedora 23 users: A new update is out addressing multiple security vulnerabilities. It's crucial to download the latest packages from upstream repositories soon.
* Re-synced to upstream sources * Security fix for CVE-2016-0720, CVE-2016-0721 * Rubygems built with RELRO * Spec file cleanup * Fixed multilib .pyc/.pyo issue ---- * Re-synced to...

Summary

pcs is a corosync and pacemaker configuration tool. It permits users to

easily view, modify and created pacemaker based clusters.

Update Information:

* Re-synced to upstream sources * Security fix for CVE-2016-0720, CVE-2016-0721 * Rubygems built with RELRO * Spec file cleanup * Fixed multilib .pyc/.pyo issue ---- * Re-synced to upstream sources * Security fix for CVE-2016-0720, CVE-2016-0721 * Rubygems built with RELRO * Spec file cleanup * Fixed multilib .pyc/.pyo issue

Change Log

References


[ 1 ] Bug #1299614 - CVE-2016-0720 pcs: Cross-Site Request Forgery in web UI https://bugzilla.redhat.com/show_bug.cgi?id=1299614 [ 2 ] Bug #1299615 - CVE-2016-0721 pcs: cookies are not invalidated upon logout https://bugzilla.redhat.com/show_bug.cgi?id=1299615

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pcs' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pcs
Product: Fedora 23
Version: 0.9.149
Release: 2.fc23
Summary: Pacemaker Configuration System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here