Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Fedora 26 Security Update: Critical Risks of Info Disclosure and Escalation

fedora
Calendar Grey April 19, 2018
Dist Fedora Esm H88
Crucial Fedora update enhances security by addressing information leak and privilege elevation flaws to strengthen user protection.
Security fix for CVE-2018-1086 and CVE-2018-1079

Summary

pcs is a corosync and pacemaker configuration tool. It permits users to

easily view, modify and create pacemaker based clusters.

Security fix for CVE-2018-1086 and CVE-2018-1079

* Tue Apr 10 2018 Ondrej Mular - 0.9.160-2

- Fixes for CVE-2018-1086 and CVE-2018-1079

* Thu Oct 19 2017 Ondrej Mular - 0.9.160-1

- Rebased to latest upstream sources (see CHANGELOG.md)

* Wed Jul 12 2017 Ondrej Mular - 0.9.159-1

- Rebased to latest upstream sources (see CHANGELOG.md)

[ 1 ] Bug #1557366 - CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure

https://bugzilla.redhat.com/show_bug.cgi?id=1557366

[ 2 ] Bug #1550243 - CVE-2018-1079 pcs: Privilege escalation via authorized user malicious REST call

https://bugzilla.redhat.com/show_bug.cgi?id=1550243

su -c 'dnf upgrade --advisory FEDORA-2018-ce5d7106d8' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 0.9.160
Release: 2.fc26
Summary: Pacemaker Configuration System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here