Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 28 Security Advisory: pcs Critical Privilege Escalation Fix

fedora
Calendar Grey April 15, 2018
Dist Fedora Esm H88
Fedora 28 release tackles essential vulnerabilities in systems, guaranteeing correct setup and safeguarding against cluster risks.
Security fix for CVE-2018-1086 and CVE-2018-1079 Rebased to latest upstream sources

Summary

pcs is a corosync and pacemaker configuration tool. It permits users to

easily view, modify and create pacemaker based clusters.

Security fix for CVE-2018-1086 and CVE-2018-1079 Rebased to latest upstream

sources

[ 1 ] Bug #1550243 - CVE-2018-1079 pcs: Privilege escalation via authorized user malicious REST call

https://bugzilla.redhat.com/show_bug.cgi?id=1550243

[ 2 ] Bug #1557366 - CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure

https://bugzilla.redhat.com/show_bug.cgi?id=1557366

su -c 'dnf upgrade pcs' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 0.9.164
Release: 1.fc28
Summary: Pacemaker Configuration System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here