-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: libqb security update
Advisory ID:       RHSA-2020:1189-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:1189
Issue date:        2020-03-31
CVE Names:         CVE-2019-12779 
====================================================================
1. Summary:

An update for libqb is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Client (v. 7) - x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64

3. Description:

The libqb packages provide a library with the primary purpose of providing
high performance client/server reusable features, such as high performance
logging, tracing, inter-process communication, and polling.

Security Fix(es):

* libqb: Insecure treatment of IPC (temporary) files (CVE-2019-12779)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.8 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1695948 - CVE-2019-12779 libqb: Insecure treatment of IPC (temporary) files

6. Package List:

Red Hat Enterprise Linux Client (v. 7):

Source:
libqb-1.0.1-9.el7.src.rpm

x86_64:
libqb-1.0.1-9.el7.i686.rpm
libqb-1.0.1-9.el7.x86_64.rpm
libqb-debuginfo-1.0.1-9.el7.i686.rpm
libqb-debuginfo-1.0.1-9.el7.x86_64.rpm

Red Hat Enterprise Linux Client Optional (v. 7):

x86_64:
libqb-debuginfo-1.0.1-9.el7.i686.rpm
libqb-debuginfo-1.0.1-9.el7.x86_64.rpm
libqb-devel-1.0.1-9.el7.i686.rpm
libqb-devel-1.0.1-9.el7.x86_64.rpm

Red Hat Enterprise Linux ComputeNode (v. 7):

Source:
libqb-1.0.1-9.el7.src.rpm

x86_64:
libqb-1.0.1-9.el7.i686.rpm
libqb-1.0.1-9.el7.x86_64.rpm
libqb-debuginfo-1.0.1-9.el7.i686.rpm
libqb-debuginfo-1.0.1-9.el7.x86_64.rpm

Red Hat Enterprise Linux ComputeNode Optional (v. 7):

x86_64:
libqb-debuginfo-1.0.1-9.el7.i686.rpm
libqb-debuginfo-1.0.1-9.el7.x86_64.rpm
libqb-devel-1.0.1-9.el7.i686.rpm
libqb-devel-1.0.1-9.el7.x86_64.rpm

Red Hat Enterprise Linux Server (v. 7):

Source:
libqb-1.0.1-9.el7.src.rpm

ppc64:
libqb-1.0.1-9.el7.ppc.rpm
libqb-1.0.1-9.el7.ppc64.rpm
libqb-debuginfo-1.0.1-9.el7.ppc.rpm
libqb-debuginfo-1.0.1-9.el7.ppc64.rpm

ppc64le:
libqb-1.0.1-9.el7.ppc64le.rpm
libqb-debuginfo-1.0.1-9.el7.ppc64le.rpm
libqb-devel-1.0.1-9.el7.ppc64le.rpm

s390x:
libqb-1.0.1-9.el7.s390.rpm
libqb-1.0.1-9.el7.s390x.rpm
libqb-debuginfo-1.0.1-9.el7.s390.rpm
libqb-debuginfo-1.0.1-9.el7.s390x.rpm
libqb-devel-1.0.1-9.el7.s390.rpm
libqb-devel-1.0.1-9.el7.s390x.rpm

x86_64:
libqb-1.0.1-9.el7.i686.rpm
libqb-1.0.1-9.el7.x86_64.rpm
libqb-debuginfo-1.0.1-9.el7.i686.rpm
libqb-debuginfo-1.0.1-9.el7.x86_64.rpm
libqb-devel-1.0.1-9.el7.i686.rpm
libqb-devel-1.0.1-9.el7.x86_64.rpm

Red Hat Enterprise Linux Server Optional (v. 7):

ppc64:
libqb-debuginfo-1.0.1-9.el7.ppc.rpm
libqb-debuginfo-1.0.1-9.el7.ppc64.rpm
libqb-devel-1.0.1-9.el7.ppc.rpm
libqb-devel-1.0.1-9.el7.ppc64.rpm

Red Hat Enterprise Linux Workstation (v. 7):

Source:
libqb-1.0.1-9.el7.src.rpm

x86_64:
libqb-1.0.1-9.el7.i686.rpm
libqb-1.0.1-9.el7.x86_64.rpm
libqb-debuginfo-1.0.1-9.el7.i686.rpm
libqb-debuginfo-1.0.1-9.el7.x86_64.rpm

Red Hat Enterprise Linux Workstation Optional (v. 7):

x86_64:
libqb-debuginfo-1.0.1-9.el7.i686.rpm
libqb-debuginfo-1.0.1-9.el7.x86_64.rpm
libqb-devel-1.0.1-9.el7.i686.rpm
libqb-devel-1.0.1-9.el7.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2019-12779
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.8_release_notes/index

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXoOcXNzjgjWX9erEAQj8xw/9GW4vOrBek7ZxoP6f+gHDmGst9HBzTf4g
qlIwS7WbPDqDGA0uCM8p6We/xEyDHt8XZlmS2aRnIJtHpPk7pelSnU6z1glAJIdK
ycyHM2Xpo2X1zQtEUXQK+LS17DQlDSSulTEzek8YUGfjFVmR6WGa8oeTMsV3xVFn
z+ynk3NeBak7BEC++PqP3B9eZG2+GjdnLQMz2LQtyGEeM/MDhUobDV7zlkImDReZ
r4xvSW+vU9lXZpZSNoPj7HISz/LwFEvzYCsdJeFFF3wm5n7149goVY2GGQn3XzcQ
qAasyc/Webcw9H43ez50o/1V7kD0rPzE1YT3vddat1uBt8id7D/a9SO4rx/wDZtb
Re8aUH7UrOucx2bc807JpYqjxuy1g4oj0CslwnScnCai35RAZq2OeiiBhESP+tsT
QdniWTWJCxvd6IT5F5tqLdC6hLxGah4Wjml09q0iOHGY3mde81igU22Pkanmn83l
5ONaK54Cd9cxiFTiiFh3MAID6X7J3Ei6yW84gJGnxX9p2eG0J7McEqBK7EaotVUK
QMt9zQ80ImbGAyfFIitFPI6VlHpSHUH40eTNeWGgKTZLM845b/5fMylJxT03aHxG
XpvYeMovXBBXDVCjEzeycdEhcOW1Sw0/tXysg2N+6etd/FnQM8RGbsoMCcrtX33R
JTgDbfods58=TmUt
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-1189:01 Moderate: libqb security update

An update for libqb is now available for Red Hat Enterprise Linux 7

Summary

The libqb packages provide a library with the primary purpose of providing high performance client/server reusable features, such as high performance logging, tracing, inter-process communication, and polling.
Security Fix(es):
* libqb: Insecure treatment of IPC (temporary) files (CVE-2019-12779)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2019-12779 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.8_release_notes/index

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: libqb-1.0.1-9.el7.src.rpm
x86_64: libqb-1.0.1-9.el7.i686.rpm libqb-1.0.1-9.el7.x86_64.rpm libqb-debuginfo-1.0.1-9.el7.i686.rpm libqb-debuginfo-1.0.1-9.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64: libqb-debuginfo-1.0.1-9.el7.i686.rpm libqb-debuginfo-1.0.1-9.el7.x86_64.rpm libqb-devel-1.0.1-9.el7.i686.rpm libqb-devel-1.0.1-9.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source: libqb-1.0.1-9.el7.src.rpm
x86_64: libqb-1.0.1-9.el7.i686.rpm libqb-1.0.1-9.el7.x86_64.rpm libqb-debuginfo-1.0.1-9.el7.i686.rpm libqb-debuginfo-1.0.1-9.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64: libqb-debuginfo-1.0.1-9.el7.i686.rpm libqb-debuginfo-1.0.1-9.el7.x86_64.rpm libqb-devel-1.0.1-9.el7.i686.rpm libqb-devel-1.0.1-9.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source: libqb-1.0.1-9.el7.src.rpm
ppc64: libqb-1.0.1-9.el7.ppc.rpm libqb-1.0.1-9.el7.ppc64.rpm libqb-debuginfo-1.0.1-9.el7.ppc.rpm libqb-debuginfo-1.0.1-9.el7.ppc64.rpm
ppc64le: libqb-1.0.1-9.el7.ppc64le.rpm libqb-debuginfo-1.0.1-9.el7.ppc64le.rpm libqb-devel-1.0.1-9.el7.ppc64le.rpm
s390x: libqb-1.0.1-9.el7.s390.rpm libqb-1.0.1-9.el7.s390x.rpm libqb-debuginfo-1.0.1-9.el7.s390.rpm libqb-debuginfo-1.0.1-9.el7.s390x.rpm libqb-devel-1.0.1-9.el7.s390.rpm libqb-devel-1.0.1-9.el7.s390x.rpm
x86_64: libqb-1.0.1-9.el7.i686.rpm libqb-1.0.1-9.el7.x86_64.rpm libqb-debuginfo-1.0.1-9.el7.i686.rpm libqb-debuginfo-1.0.1-9.el7.x86_64.rpm libqb-devel-1.0.1-9.el7.i686.rpm libqb-devel-1.0.1-9.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64: libqb-debuginfo-1.0.1-9.el7.ppc.rpm libqb-debuginfo-1.0.1-9.el7.ppc64.rpm libqb-devel-1.0.1-9.el7.ppc.rpm libqb-devel-1.0.1-9.el7.ppc64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source: libqb-1.0.1-9.el7.src.rpm
x86_64: libqb-1.0.1-9.el7.i686.rpm libqb-1.0.1-9.el7.x86_64.rpm libqb-debuginfo-1.0.1-9.el7.i686.rpm libqb-debuginfo-1.0.1-9.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64: libqb-debuginfo-1.0.1-9.el7.i686.rpm libqb-debuginfo-1.0.1-9.el7.x86_64.rpm libqb-devel-1.0.1-9.el7.i686.rpm libqb-devel-1.0.1-9.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:1189-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:1189
Issued Date: : 2020-03-31
CVE Names: CVE-2019-12779

Topic

An update for libqb is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64

Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - ppc64

Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64


Bugs Fixed

1695948 - CVE-2019-12779 libqb: Insecure treatment of IPC (temporary) files


Related News