Low: fence security, bug fix, and enhancement update. Date: Thu, 24 Feb 2011 13:45:18 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Low: fence on SL4.x i386/x86_64 Comments: To: "
fence contains multiple programs containing vulnerabilites that may allow local users to overwrite arbitrary files via a symlink attack.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201009-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: fence: Multiple symlink vulnerabilites Date: September 29, 2010 Bugs: #240576 ID: 201009-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= fence contains multiple programs containing vulnerabilites that may allow local users to overwrite arbitrary files via a symlink attack. Background ========= fence is an I/O group fencing system. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-cluster/fence < 2.03.09 Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package if one is available or wait for the existing packages to be marked stable by their architecture maintainers. Description ========== The fence_apc, fence_apc_snmp (CVE-2008-4579) and fence_manual (CVE-2008-4580) programs contain symlink vulnerabilites. Impact ===== These vulnerabilities may allow arbitrary files to be overwritten with root privileges. Workaround ========= There is no known workaround at this time. Resolution ========= Gentoo discontinued support for fence. All fence users should uninstall and choose another software that provides the same functionality. # emerge--unmerge sys-cluster/fence References ========= [ 1 ] CVE-2008-4579 https://www.cve.org/CVERecord?id=CVE-2008-4579 [ 2 ] CVE-2008-4580 https://www.cve.org/CVERecord?id=CVE-2008-4580 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201009-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Updated upstream sources.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-463 2005-06-29 ---------------------------------------------------------------------Product : Fedora Core 4 Name : fence Version : 1.32.1 Release : 1 Summary : fence - The cluster I/O fencing system Description : The cluster I/O fencing system (fence) provides fencing agents which connect to a variety of network power switch/fibre channel switches/etc. to forcibly remove unresponsive machines from a cluster. ---------------------------------------------------------------------Update Information: Updated upstream sources. ------------------------------------------------------------------------------------------------------------------------------------------This update can be downloaded from: b91f6ffdab03c5da23e28a56a4c9345b SRPMS/fence-1.32.1-1.src.rpm 8c32515f3e3196ca2eefee2d8f5d725b ppc/fence-1.32.1-1.ppc.rpm 5049b33e70fdec76bd5964e840793d98 ppc/debug/fence-debuginfo-1.32.1-1.ppc.rpm 5a6b4b5a0cfc8a8acad27bab7d96c3f9 x86_64/fence-1.32.1-1.x86_64.rpm 07b3fa25737a3a91065f391a51769043 x86_64/debug/fence-debuginfo-1.32.1-1.x86_64.rpm 6215bc48bf2e7e082c6035f5ecdfd01e i386/fence-1.32.1-1.i386.rpm af5c6ddee6fad3e1ba4aa0f59e11fa63 i386/debug/fence-debuginfo-1.32.1-1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.