Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Red Hat OpenShift 3.1.0 RHSA-2015:2901-02 Critical Buffer Overflow Issue

red hat
Calendar Grey December 17, 2015
Scroller Redhat
Red Hat OpenShift Enterprise version 2.2.8 has been released, which tackles a significant security vulnerability alongside several bug corrections.
Red Hat OpenShift Enterprise release 2.2.8, which fixes one security issue, several bugs, and introduces feature enhancements, is now available

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

See the OpenShift Enterprise 2.2 Release Notes, which will be updated shortly for release 2.2.8, for important instructions on how to fully apply this asynchronous errata update:

ingle/2.2_Release_Notes/index.html#chap-Asynchronous_Errata_Updates

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at: https://access.redhat.com/articles/11258

Summary

OpenShift Enterprise by Red Hat is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
The following security issue is addressed with this release:
An implementation error related to the memory management of request and responses was found within HAProxy's buffer_slow_realign() function. An unauthenticated remote attacker could use this flaw to leak certain memory buffer contents from a past request or session. (CVE-2015-3281)
Space precludes documenting all of the bug fixes in this advisory. See the OpenShift Enterprise Technical Notes, which will be updated shortly for release 2.2.8, for details about these changes:
ingle/Technical_Notes/index.html
All OpenShift Enterprise 2 users are advised to upgrade to these updated packages.

References

https://access.redhat.com/security/cve/CVE-2015-3281 https://access.redhat.com/security/updates/classification#important

Package List

RHOSE Client 2.2:
Source: rhc-1.38.4.5-1.el6op.src.rpm
noarch: rhc-1.38.4.5-1.el6op.noarch.rpm
RHOSE Infrastructure 2.2:
Source: openshift-enterprise-upgrade-2.2.8-1.el6op.src.rpm openshift-origin-broker-util-1.37.4.2-1.el6op.src.rpm rubygem-openshift-origin-common-1.29.4.1-1.el6op.src.rpm rubygem-openshift-origin-controller-1.38.4.2-1.el6op.src.rpm rubygem-openshift-origin-routing-daemon-0.26.4.4-1.el6op.src.rpm
noarch: openshift-enterprise-release-2.2.8-1.el6op.noarch.rpm openshift-enterprise-upgrade-broker-2.2.8-1.el6op.noarch.rpm openshift-enterprise-yum-validator-2.2.8-1.el6op.noarch.rpm openshift-origin-broker-util-1.37.4.2-1.el6op.noarch.rpm rubygem-openshift-origin-common-1.29.4.1-1.el6op.noarch.rpm rubygem-openshift-origin-controller-1.38.4.2-1.el6op.noarch.rpm rubygem-openshift-origin-routing-daemon-0.26.4.4-1.el6op.noarch.rpm
RHOSE JBoss EAP add-on 2.2:
Source: openshift-origin-cartridge-jbosseap-2.27.3.1-1.el6op.src.rpm
noarch: openshift-origin-cartridge-jbosseap-2.27.3.1-1.el6op.noarch.rpm
RHOSE Node 2.2:
Source: haproxy15side-1.5.4-2.el6op.src.rpm openshift-enterprise-upgrade-2.2.8-1.el6op.src.rpm openshift-origin-cartridge-haproxy-1.31.4.1-1.el6op.src.rpm openshift-origin-cartridge-jbossews-1.35.3.2-1.el6op.src.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2015:2666-01
Product: Red Hat OpenShift Enterprise
Issue date: 2015-12-17

Topic

Red Hat OpenShift Enterprise release 2.2.8, which fixes one securityissue, several bugs, and introduces feature enhancements, is nowavailable.Red Hat Product Security has rated this update as having Importantsecurity impact. Common Vulnerability Scoring System (CVSS) basescores, which give detailed severity ratings, are available for eachvulnerability from the CVE links in the References section.

Relevant Releases Architectures

RHOSE Client 2.2 - noarch

RHOSE Infrastructure 2.2 - noarch

RHOSE JBoss EAP add-on 2.2 - noarch

RHOSE Node 2.2 - noarch, x86_64

Bugs Fixed

1045226 - oo-auto-idler man page incorrect

1054441 - oo-accept-node should test that BROKER_HOST is consistent

1064039 - RFE oo-diagnostics should report when node auth is failing (401 Unauthorized)

1101973 - oo-diagnostics tools is checking a non-existing dir after update ose-2.0 GA to ose-2.0.z puddle + RHSCL-1.1

1110415 - `oo-admin-broker-cache --clear --console` does not warn that --console flag does nothing

1111501 - REPORT_BUILD_ANALYTICS should be set to false by default

1111598 - oo-admin-chk gives bad advice to users when gears do not exist on the node.

1139608 - rhc snapshot save different app with the same name in the same dir didn't prompt conflict information

1140766 - oo-admin-ctl-district doesn't suggest FQDN for -i in -h output

1155003 - Should prompt correct and important parameter information when use none or error parameter in "rhc server add" command

1177753 - Enable a configuration in rhc to use a different ssh executable

1211526 - HAProxy does not restart when pid is not found

1218872 - rhc setup fail during upload sshkey

1238305 - [RFE] gear-placement plugin domain_id as input data

1239072 - CVE-2015-3281 haproxy: information leak in buffer_slow_realign()

1241675 - [RFE] Check for missing openshift_application_aliases components f5-icontrol-rest.rb

1248439 - Routing SPI for Nginx doesn't preserve host in http request's headers1255426 - API Call to disable HA does not remove 2nd haproxy head gear

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.