Updated ccs packages that fix one security issue are now available for Red Hat Cluster Suite 4. The Red Hat Security Response Team has rated this update as having low [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Low: ccs security update Advisory ID: RHSA-2011:0265-01 Product: Red Hat Cluster Suite Advisory URL: https://access.redhat.com/errata/RHSA-2011:0265.html Issue date: 2011-02-16 CVE Names: CVE-2008-6552 ==================================================================== 1. Summary: Updated ccs packages that fix one security issue are now available for Red Hat Cluster Suite 4. The Red Hat Security Response Team has rated this update as having low security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Cluster Suite 4AS - i386, ia64, ppc, x86_64 Red Hat Cluster Suite 4ES - i386, ia64, x86_64 Red Hat Cluster Suite 4WS - i386, ia64, x86_64 3. Description: The Cluster Configuration System provides the ability for nodes in a cluster to obtain information about the cluster and each other. ccs_tool is a program for making online updates to the cluster configuration file. An insecure temporary file use flaw was found in ccs_tool. A local attacker could use this flaw to conduct a symbolic link attack, allowing them to overwrite (with the output of ccs_tool) an arbitrary file writable by the victim running ccs_tool. (CVE-2008-6552) All ccs users should upgrade to these updated packages, which correct this issue. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed(http://bugzilla.redhat.com/): 498980 - cluster product is affected by several symlink attack vulnerabilities 519436 - CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file use issues 6. Package List: Red Hat Cluster Suite 4AS: Source: i386: ccs-1.0.13-2.i686.rpm ccs-debuginfo-1.0.13-2.i686.rpm ccs-devel-1.0.13-2.i686.rpm ia64: ccs-1.0.13-2.ia64.rpm ccs-debuginfo-1.0.13-2.ia64.rpm ccs-devel-1.0.13-2.ia64.rpm ppc: ccs-1.0.13-2.ppc64.rpm ccs-debuginfo-1.0.13-2.ppc64.rpm ccs-devel-1.0.13-2.ppc64.rpm x86_64: ccs-1.0.13-2.x86_64.rpm ccs-debuginfo-1.0.13-2.x86_64.rpm ccs-devel-1.0.13-2.x86_64.rpm Red Hat Cluster Suite 4ES: Source: i386: ccs-1.0.13-2.i686.rpm ccs-debuginfo-1.0.13-2.i686.rpm ccs-devel-1.0.13-2.i686.rpm ia64: ccs-1.0.13-2.ia64.rpm ccs-debuginfo-1.0.13-2.ia64.rpm ccs-devel-1.0.13-2.ia64.rpm x86_64: ccs-1.0.13-2.x86_64.rpm ccs-debuginfo-1.0.13-2.x86_64.rpm ccs-devel-1.0.13-2.x86_64.rpm Red Hat Cluster Suite 4WS: Source: i386: ccs-1.0.13-2.i686.rpm ccs-debuginfo-1.0.13-2.i686.rpm ccs-devel-1.0.13-2.i686.rpm ia64: ccs-1.0.13-2.ia64.rpm ccs-debuginfo-1.0.13-2.ia64.rpm ccs-devel-1.0.13-2.ia64.rpm x86_64: ccs-1.0.13-2.x86_64.rpm ccs-debuginfo-1.0.13-2.x86_64.rpm ccs-devel-1.0.13-2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2008-6552 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. . Revamped ccs libraries address a minor vulnerability in Red Hat Cluster Suite 4 featuring advisory specifics.. Red Hat Security, ccs update, Cluster Suite, security advisory. . Severity: Low. LinuxSecurity.com Team
Updated GFS & Cluster Suite packages for the latest kernel (kernel-2.6.15-1.1831_FC4). . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-120 2006-02-22 ---------------------------------------------------------------------Product : Fedora Core 4 Name : dlm-kernel Version : 2.6.11.5 Release : 20050601.152643.FC4.21 Summary : dlm-kernel - The Distributed Lock Manager kernel modules. Description : dlm-kernel - The Distributed Lock Manager kernel modules. ---------------------------------------------------------------------Update Information: Updated GFS & Cluster Suite packages for the latest kernel (kernel-2.6.15-1.1831_FC4). ------------------------------------------------------------------------------------------------------------------------------------------This update can be downloaded from: 8e6b792f061fbf1e91ed28df1b708be69cb878dd SRPMS/dlm-kernel-2.6.11.5-20050601.152643.FC4.21.src.rpm be3254a43fd35b0330112008423a29e228eb2e63 ppc/dlm-kernel-2.6.11.5-20050601.152643.FC4.21.ppc.rpm 763123ca6ca0a51c7734b6f5610cf0f11cb15f43 ppc/dlm-kernheaders-2.6.11.5-20050601.152643.FC4.21.ppc.rpm c1dc1f960b6ade5f327bb4967d2e84995fa0a6fd ppc/debug/dlm-kernel-debuginfo-2.6.11.5-20050601.152643.FC4.21.ppc.rpm 0ceb9271241446c2c06452046b31327f5cb25c39 x86_64/dlm-kernel-2.6.11.5-20050601.152643.FC4.21.x86_64.rpm 1bade25b42559e9c1956472f198e1901f841cc5e x86_64/dlm-kernheaders-2.6.11.5-20050601.152643.FC4.21.x86_64.rpm b9583c4e96559551c259db28aab9279131fe1ff4 x86_64/dlm-kernel-smp-2.6.11.5-20050601.152643.FC4.21.x86_64.rpm 8fae97d5d104142a7185ec51eff2cafb185ff444 x86_64/debug/dlm-kernel-debuginfo-2.6.11.5-20050601.152643.FC4.21.x86_64.rpm 7c1c49deadc5c4a2435ba540abb6fba19795aa43 i386/dlm-kernel-2.6.11.5-20050601.152643.FC4.21.i586.rpm c779b4504e5235d74d1c2034755766a08a4a3d80 i386/dlm-kernheaders-2.6.11.5-20050601.152643.FC4.21.i586.rpm 5b1f6bed2c66160f9f69042d1cebb7f9112a44ae i386/debug/dlm-kernel-debuginfo-2.6.11.5-20050601.152643.FC4.21.i586.rpm 6dfcc153a58496e2a4eb0c0b345558c18da3b7fc i386/dlm-kernel-2.6.11.5-20050601.152643.FC4.21.i686.rpm c3d2c1f1991a4172ab0c05347f1e5fdfdace4c50 i386/dlm-kernheaders-2.6.11.5-20050601.152643.FC4.21.i686.rpm 65123695e44710a6085970ab57732fe4100e9c04 i386/dlm-kernel-smp-2.6.11.5-20050601.152643.FC4.21.i686.rpm 18ef3587f0a2986404662acdbf795886f2c79691 i386/debug/dlm-kernel-debuginfo-2.6.11.5-20050601.152643.FC4.21.i686.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.