Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-ea8f4e232d 2022-07-30 01:52:05.591840 --------------------------------------------------------------------------------Name : golang-github-hashicorp-consul-migrate Product : Fedora 36 Version : 0.1.0 Release : 10.20190602git678fb10.fc36 URL : https://github.com/hashicorp/consul-migrate Summary : Consul server data migrator Description : Consul-migrate is a Go package and CLI utility to perform a very specific data migration for Consul servers nodes. Between Consul versions 0.5.0 and 0.5.1, the backend for storing Raft data was changed from LMDB to BoltDB. To support seamless upgrades, this library is embedded in Consul version 0.5.1 to perform the upgrade automatically. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G - 0.1.0-10 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-ea8f4e232d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The package consul before version 1.9.8-1 is vulnerable to multiple issues including access restriction bypass and certificate verification bypass. . Arch Linux Security Advisory ASA-202107-69 ========================================= Severity: Medium Date : 2021-07-27 CVE-ID : CVE-2021-32574 CVE-2021-36213 Package : consul Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2171 Summary ====== The package consul before version 1.9.8-1 is vulnerable to multiple issues including access restriction bypass and certificate verification bypass. Resolution ========= Upgrade to 1.9.8-1. # pacman -Syu "consul> =1.9.8-1" The problems have been fixed upstream in version 1.9.8. Workaround ========= None. Description ========== - CVE-2021-32574 (certificate verification bypass) HashiCorp Consul before version 1.9.8 does not validate SSL certificates correctly: xds does not ensure that the Subject Alternative Name of an upstream is validated. - CVE-2021-36213 (access restriction bypass) In HashiCorp Consul before version 1.9.8, xds can generate a situation where a single L7 deny intention (with a default deny policy) results in an allow action. Impact ===== A single L7 deny intention could erroneously result in an allow action, leading to access restriction bypass. Furthermore, a malicious upstream could present an invalidcertificate. References ========= https://discuss.hashicorp.com/t/hcsec-2021-17-consul-s-envoy-tls-configuration-did-not-validate-destination-service-subject-alternative-names/26856 https://github.com/hashicorp/consul/issues/6364 https://github.com/hashicorp/consul/pull/10621 https://github.com/hashicorp/consul/pull/10623 https://github.com/hashicorp/consul/commit/2bca52fa88caedc2b6a7cc3627f3cd1f683c6d74 https://github.com/hashicorp/consul/commit/0b4fe4b7a2a7c400521248a0d548429963f4c614 https://discuss.hashicorp.com/t/hcsec-2021-16-consul-s-application-aware-intentions-deny-action-fails-open-when-combined-with-default-deny-policy/26855 https://github.com/hashicorp/consul/pull/10619 https://github.com/hashicorp/consul/pull/10620 https://github.com/hashicorp/consul/commit/3ca24425ef7ad223077269a42041622f269ef5d0 https://security.archlinux.org/CVE-2021-32574 https://security.archlinux.org/CVE-2021-36213 . Several concerns impacting Consul on Arch Linux necessitate prompt patches to improve safety; advisory seriousness is moderate.. Consul Security Advisory, Arch Linux Vulnerabilities, Remote Access Control, Certificate Issues, Security Patches. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.