An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for etcd ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0330-1 Rating: important References: #1095184 #1118897 #1121850 Cross-References: CVE-2018-16873 CVE-2018-16886 Affected Products: SUSE CaaS Platform 3.0 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for etcd to version 3.3.11 fixes the following issues: Security vulnerabilities addressed: - CVE-2018-16886: Fixed an improper authentication issue when role-based access control (RBAC) was used and client-cert-auth were enabled. This allowed an remote attacker to authenticate as user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway. (bsc#1121850) - CVE-2018-16873: Fixed an issue with the go get command, which allowed for remote code execution when being executed with the -u flag (bsc#1118897) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE CaaS Platform 3.0 (x86_64): etcd-3.3.11-3.6.1 etcdctl-3.3.11-3.6.1 References: https://www.suse.com/security/cve/CVE-2018-16873.html https://www.suse.com/security/cve/CVE-2018-16886.html https://bugzilla.suse.com/1095184 https://bugzilla.suse.com/1118897 https://bugzilla.suse.com/1121850 _______________________________________________ sle-security-updates mailing list
Updated GFS & Cluster Suite packages for the latest kernel (kernel-2.6.15-1.1831_FC4). . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-120 2006-02-22 ---------------------------------------------------------------------Product : Fedora Core 4 Name : GFS-kernel Version : 2.6.11.8 Release : 20050601.152643.FC4.24 Summary : GFS-kernel - The Global File System kernel modules Description : GFS - The Global File System is a symmetric, shared-disk, cluster file system. ---------------------------------------------------------------------Update Information: Updated GFS & Cluster Suite packages for the latest kernel (kernel-2.6.15-1.1831_FC4). ------------------------------------------------------------------------------------------------------------------------------------------This update can be downloaded from: abbb34703eba3f06adfb0ad6379e78a4ef34db94 SRPMS/GFS-kernel-2.6.11.8-20050601.152643.FC4.24.src.rpm 470c6c67efb84814144a5ecf79d314ce0d87e3cd ppc/GFS-kernel-2.6.11.8-20050601.152643.FC4.24.ppc.rpm ea84dc0d07c74acf23da15626ca7a4406490dd59 ppc/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.24.ppc.rpm a74e82bfefe4b39d1aa0adb9cf66968611673544 ppc/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.24.ppc.rpm 2703184ad743841e23f788bd86a000979ff40a89 x86_64/GFS-kernel-2.6.11.8-20050601.152643.FC4.24.x86_64.rpm edb7c34653b05e89c6a251a6c6297fe16741f2c8 x86_64/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.24.x86_64.rpm 316d3d6593805ee808c000465b84ba4eac78e605 x86_64/GFS-kernel-smp-2.6.11.8-20050601.152643.FC4.24.x86_64.rpm bdb4f899c42988dbbe4c2d457411f737f1eb4c66 x86_64/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.24.x86_64.rpm ffc4b5f0b93cecb7a9f995c243d114e6d17266fe i386/GFS-kernel-2.6.11.8-20050601.152643.FC4.24.i586.rpm f98118777498e7d2f97eeb6f46b46e72b14037d2 i386/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.24.i586.rpm 373f4ffb91a406f23129ac97c044b637704cde6d i386/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.24.i586.rpm 584c0dc1c502efb992fd19721c1a1f4d84789b29 i386/GFS-kernel-2.6.11.8-20050601.152643.FC4.24.i686.rpm 1fd363509d1e578fd03b6e157b3eab3ce3375e32 i386/GFS-kernheaders-2.6.11.8-20050601.152643.FC4.24.i686.rpm 99c4c53e02832d96d25be4c0ac71205bb057aa9b i386/GFS-kernel-smp-2.6.11.8-20050601.152643.FC4.24.i686.rpm 0007acbc1d6f73ff22e95490975caac2181e9384 i386/debug/GFS-kernel-debuginfo-2.6.11.8-20050601.152643.FC4.24.i686.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.