Before applying this update, make sure all previously-released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
Red Hat Enterprise MRG (Messaging, Realtime, and Grid) is a realtime IT
infrastructure for enterprise computing. MRG Messaging uses Apache Qpid to
implement the Advanced Message Queuing Protocol (AMQP) standard, adding
persistence options, kernel optimizations, and operating system services.
This update moves Red Hat Enterprise MRG to version 1.3.
A flaw was found in the way Apache Qpid handled the receipt of invalid AMQP
data. A remote user could send invalid AMQP data to the server, causing it
to crash, resulting in the cluster shutting down. (CVE-2009-5005)
A flaw was found in the way Apache Qpid handled a request to redeclare an
existing exchange while adding a new alternate exchange. If a remote,
authenticated user issued such a request, the server would crash, resulting
in the cluster shutting down. (CVE-2009-5006)
This update also adds the following enhancements:
* This update introduces a protocol-independent C++ API. The extra layer of
indirection will make it easy to support new versions of the AMQP protocol,
as well as multiple versions simultaneously. (BZ#497747)
* The management component is now capable of working in a cluster.
(BZ#501015)
* The Messaging Client Python API is now protocol-independent. (BZ#497748)
* This update allows a JMS client to subscribe to the failover exchange to
retrieve cluster membership information and subsequently to receive
updates. (BZ#483753)
* With this update, the qpidd service can be run without additional
authentication options. (BZ#515513)
* This update adds an OpenMPI wrapper script to Condor. It adds support for
OpenMPI jobs. (BZ#537232)
* The Messaging Client Python API now provides a failover mechanism for
clustered brokers. (BZ#495718)
* The Python Messaging API now includes support for Simple Authentication
and Security Layer (SASL), which allows authentication support to be added
to connection-based protocols. (BZ#548493)
* The qpid-tool is now able to determine which session a queue consumer
belongs to. (BZ#504325)
* This update handles backward/forward compatibility for QMF and its
components. (BZ#506698)
* Both Secure Sockets Layer (SSL) and Remote Direct Memory Access (RDMA)
entries can now appear in the list of known URLs. (BZ#471632)
* This update allows for the scheduler daemon to run without swap.
(BZ#548090)
* This update introduces a mechanism that specifies the queue size of a
queue that is setup via the Java API. (BZ#534008)
* Previously, a collector could not be remotely restarted. With this
update, the restart is possible and works as expected. (BZ#543021)
* The usage information for the qpid-config utility (that is, the output of
the "qpid-config -h" command) has been updated to include a brief
explanation of the exchange type. (BZ#506420)
These updated packages include many other bug fixes and enhancements. Usersare directed to the Red Hat Enterprise MRG 1.3 Technical Notes for
information on these changes:
https://access.redhat.com/search/
otes/index.html
All Red Hat Enterprise MRG users are advised to upgrade to these updated
packages, which resolve these issues and add these enhancements, as well as
resolving the issues and adding the enhancements noted in the Red Hat
Enterprise MRG 1.3 Technical Notes. After installing the updated packages,
the qpidd service must be restarted ("service qpidd restart") for this
update to take effect.
https://access.redhat.com/security/cve/CVE-2009-5005 https://access.redhat.com/security/cve/CVE-2009-5006 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/search/
MRG Grid for RHEL 5 Server:
Source:
i386:
PyYAML-3.08-5.el5.i386.rpm
PyYAML-debuginfo-3.08-5.el5.i386.rpm
classads-1.0.8-1.el5.i386.rpm
classads-debuginfo-1.0.8-1.el5.i386.rpm
classads-devel-1.0.8-1.el5.i386.rpm
classads-static-1.0.8-1.el5.i386.rpm
condor-7.4.4-0.16.el5.i386.rpm
condor-debuginfo-7.4.4-0.16.el5.i386.rpm
condor-kbdd-7.4.4-0.16.el5.i386.rpm
condor-qmf-7.4.4-0.16.el5.i386.rpm
condor-vm-gahp-7.4.4-0.16.el5.i386.rpm
libyaml-0.1.2-4.el5.i386.rpm
libyaml-debuginfo-0.1.2-4.el5.i386.rpm
libyaml-devel-0.1.2-4.el5.i386.rpm
ruby-sqlite3-1.2.4-1.el5.i386.rpm
ruby-sqlite3-debuginfo-1.2.4-1.el5.i386.rpm
noarch:
condor-ec2-enhanced-1.1-1.el5.noarch.rpm
condor-ec2-enhanced-hooks-1.1-1.el5.noarch.rpm
condor-job-hooks-1.4-5.el5.noarch.rpm
condor-low-latency-1.1-0.2.el5.noarch.rpm
condor-wallaby-base-db-1.4-5.el5.noarch.rpm
condor-wallaby-client-3.6-6.el5.noarch.rpm
condor-wallaby-tools-3.6-6.el5.noarch.rpm
mrg-grid-docs-1.3-1.el5.noarch.rpm
mrg-release-1.3-2.el5.noarch.rpm
python-condorec2e-1.1-1.el5.noarch.rpm
python-condorutils-1.4-5.el5.noarch.rpm
python-wallabyclient-3.6-6.el5.noarch.rpm
ruby-rhubarb-0.2.7-1.el5.noarch.rpm
ruby-spqr-0.3.2-1.el5.noarch.rpm
ruby-wallaby-0.9.18-2.el5.noarch.rpm
spqr-gen-0.3.2-1.el5.noarch.rpm
wallaby-0.9.18-2.el5.noarch.rpm
Read the Full Advisory
Updated packages that fix two security issues, several bugs, and addmultiple enhancements are now available as part of the ongoing support andmaintenance of Red Hat Enterprise MRG Messaging and Grid for Red HatEnterprise Linux 5.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. Common Vulnerability Scoring System (CVSS) base scores,which give detailed severity ratings, are available for each vulnerabilityfrom the CVE links in the References section.
MRG Grid Execute Node for RHEL 5 Server - i386, noarch, x86_64
MRG Grid for RHEL 5 Server - i386, noarch, x86_64
MRG Management for RHEL 5 Server - i386, noarch, x86_64
MRG Realtime for RHEL 5 Server - noarch
Red Hat MRG Messaging Base for RHEL 5 Server - i386, noarch, x86_64
Red Hat MRG Messaging for RHEL 5 Server - i386, noarch, x86_64
445749 - [python client] kerberos based authentication
452546 - No way to determine if session/connection is established
455318 - A tx commit fails without a proper error message when a queue runs out of capacity
456482 - submit -spool and transfer_executable = false
458344 - Messages are not released on rollback
462461 - Clustering broker fail-over must replicate federation links
469919 - qpidd init script over-rides user option settings.
470080 - Cluster integration with security.
471054 - focus linking of gsoap, X11 and pq into daemons and tools
471286 - Grid Statistics Job Activity Graphics doesn't update correctly
471315 - Grid, Parse error on Hold a job reason entry.
471326 - Grid: It appears that the default for jobs is to show up as held in the boxed graphic
471632 - Add support for SSL/RDMA URLs in cluster's know urls list
479031 - Cluster member can't be added while management session open
479326 - cluster broker crashes with race condition in DispatchHandle
482944 - Management messages can get staged - which breaks management
483666 - Dynamic Slots and STARTD_JOB_EXPRS, invalid attribute name
483753 - Add failover exchange support for the java client
484048 - qpidd+store flush() failed: jexception 0x0106 slock::slo ck() threw JERR__PTHREAD: pthread failure. (pthread_mutex_lock failed: errno=22 (Invalid argument)) (MessageStoreImpl.cpp:1331)
485091 - "Unknown Publisher" when installing Windows grid client
Get the latest Linux and open source security news straight to your inbox.