Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Scientific Linux: 2016:2596-2 Moderate: pcs CSRF and Fixation Issues

Scientific Large Esm H500
Moderate: pcs security, bug fix, and enhancement update
Date: Wed, 14 Dec 2016 17:52:19 -0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Scott Reid 
Subject: Security ERRATA Moderate: pcs on SL7.x x86_64
MIME-Version: 1.0
Message-ID: <20161214175219.3169.49291@slpackages.fnal.gov>

Synopsis: Moderate: pcs security, bug fix, and enhancement update
Advisory ID: SLSA-2016:2596-2
Issue Date: 2016-11-03
CVE Numbers: CVE-2016-0720
 CVE-2016-0721
--

The following packages have been upgraded to a newer upstream version: pcs
(0.9.152).

Security Fix(es):

* A Cross-Site Request Forgery (CSRF) flaw was found in the pcsd web UI. A
remote attacker could provide a specially crafted web page that, when
visited by a user with a valid pcsd session, would allow the attacker to
trigger requests on behalf of the user, for example removing resources or
restarting/removing nodes. (CVE-2016-0720)

* It was found that pcsd did not invalidate cookies on the server side
when a user logged out. This could potentially allow an attacker to
perform session fixation attacks on pcsd. (CVE-2016-0721)

These issues were discovered by Martin Prpic (Red Hat Product Security).

Additional Changes:
--

SL7
 x86_64
 pcs-0.9.152-10.el7.x86_64.rpm
 pcs-debuginfo-0.9.152-10.el7.x86_64.rpm

- Scientific Linux Development Team

Related News

Your message here