Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Fedora 25 PC Security Update: Addressing Critical XSS Vulnerability Fix

fedora
Calendar Grey April 3, 2017
Scroller Fedora
Essential Fedora security patch tackles potential XSS vulnerability in pcs by correcting node name validation flaws. Update immediately!
- Security fix for CVE-2017-2661: Improper node name field validation when creating clusters leads to XSS - Re-added support for clufter as it is now available for Python 3

Summary

pcs is a corosync and pacemaker configuration tool. It permits users to

easily view, modify and create pacemaker based clusters.

Update Information:

- Security fix for CVE-2017-2661: Improper node name field validation when creating clusters leads to XSS - Re-added support for clufter as it is now available for Python 3

Change Log

References


[ 1 ] Bug #1428948 - CVE-2017-2661 pcs: Improper node name field validation when creating clusters leads to XSS https://bugzilla.redhat.com/show_bug.cgi?id=1428948

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade pcs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pcs
Product: Fedora 25
Version: 0.9.156
Release: 2.fc25
Summary: Pacemaker Configuration System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.