Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 30: 2019-af0cd1b8f7 Critical: Openwsman Buffer Disclosure and DoS

fedora
Calendar Grey March 29, 2019
Dist Fedora Esm H88
Critical openwsman update for Fedora 30 to address file disclosure and DoS issues. See advisory details.
Security fixes for CVE-2019-3816 and CVE-2019-3833

Summary

Openwsman is a project intended to provide an open-source

implementation of the Web Services Management specification

(WS-Management) and to expose system management information on the

Linux operating system using the WS-Management protocol. WS-Management

is based on a suite of web services specifications and usage

requirements that exposes a set of operations focused on and covers

all system management aspects.

Security fixes for CVE-2019-3816 and CVE-2019-3833

[ 1 ] Bug #1667070 - CVE-2019-3816 openwsman: Disclosure of arbitrary files outside of the registered URIs

https://bugzilla.redhat.com/show_bug.cgi?id=1667070

[ 2 ] Bug #1674478 - CVE-2019-3833 openwsman: Infinite loop in process_connection() allows denial of service

https://bugzilla.redhat.com/show_bug.cgi?id=1674478

su -c 'dnf upgrade --advisory FEDORA-2019-af0cd1b8f7' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 2.6.8
Release: 5.fc30
URL:
Summary: Open source Implementation of WS-Management

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here