Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 28: FEDORA-2019-348166f7fd Critical: Openwsman DoS

fedora
Calendar Grey March 28, 2019
Dist Fedora Esm H88
Updates for openwsman in Fedora to resolve severe file exposure and service interruption vulnerabilities. Discover further details here.
Security fixes for CVE-2019-3816 and CVE-2019-3833

Summary

Openwsman is a project intended to provide an open-source

implementation of the Web Services Management specification

(WS-Management) and to expose system management information on the

Linux operating system using the WS-Management protocol. WS-Management

is based on a suite of web services specifications and usage

requirements that exposes a set of operations focused on and covers

all system management aspects.

Security fixes for CVE-2019-3816 and CVE-2019-3833

* Wed Mar 13 2019 Vitezslav Crhonek - 2.6.5-4

- Fix CVE-2019-3816

Resolves: #1687760

- Fix CVE-2019-3833

Resolves: #1687762

* Wed Feb 21 2018 Vitezslav Crhonek - 2.6.5-3

- Fix wrong SSL_CTX_set_cipher_list() retval check

- Explicitly disable build of java bindings (build fails if java-devel is installed)

[ 1 ] Bug #1667070 - CVE-2019-3816 openwsman: Disclosure of arbitrary files outside of the registered URIs

https://bugzilla.redhat.com/show_bug.cgi?id=1667070

[ 2 ] Bug #1674478 - CVE-2019-3833 openwsman: Infinite loop in process_connection() allows denial of service

https://bugzilla.redhat.com/show_bug.cgi?id=1674478

su -c 'dnf upgrade --advisory FEDORA-2019-348166f7fd' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 2.6.5
Release: 4.fc28
URL:
Summary: Open source Implementation of WS-Management

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here