Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 589
Alerts This Week
Warning Icon 1 589

Red Hat: RHSA-2016:2675-01 Critical: Packet IPC Flaw Exploit

red hat
Calendar Grey November 8, 2016
Scroller Redhat
Red Hat releases a significant security patch for pacemaker in RHEL 6 to mitigate a critical IPC vulnerability. Discover more details.
An update for pacemaker is now available for Red Hat Enterprise Linux 6

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The Pacemaker cluster resource manager is a collection of technologies working together to provide data integrity and the ability to maintain application availability in the event of a failure.
Security Fix(es):
* An authorization flaw was found in Pacemaker, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine. (CVE-2016-7035)
This issue was discovered by Jan "poki" Pokorny (Red Hat) and Alain Moulle (ATOS/BULL).

References

https://access.redhat.com/security/cve/CVE-2016-7035 https://access.redhat.com/security/updates/classification#important

Package List

Red Hat Enterprise Linux High Availability (v. 6):
Source: pacemaker-1.1.14-8.el6_8.2.src.rpm
i386: pacemaker-1.1.14-8.el6_8.2.i686.rpm pacemaker-cli-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cts-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-doc-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-remote-1.1.14-8.el6_8.2.i686.rpm
x86_64: pacemaker-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cli-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cts-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-doc-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-remote-1.1.14-8.el6_8.2.x86_64.rpm
Red Hat Enterprise Linux Resilient Storage (v. 6):
Source: pacemaker-1.1.14-8.el6_8.2.src.rpm
i386: pacemaker-1.1.14-8.el6_8.2.i686.rpm pacemaker-cli-1.1.14-8.el6_8.2.i686.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2016:2675-01
Product: Red Hat Enterprise Linux
Issue date: 2016-11-08

Topic

An update for pacemaker is now available for Red Hat Enterprise Linux 6.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux High Availability (v. 6) - i386, x86_64

Red Hat Enterprise Linux Resilient Storage (v. 6) - i386, x86_64

Bugs Fixed

1369732 - CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.