Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
libcgroup: cgrulesengd creates log files with insecure permissions (CVE-2018-14348) SL7 x86_64 libcgroup-0.41-21.el7.i686.rpm libcgroup-tools-0.41-21.el7.x86_64.rpm libcgroup-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.i686.rpm libcgroup-pam-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.x86_64.rpm libcgroup-pam-0.41-21.el7.i686.rpm libcgroup-debug [More...]. Synopsis: Moderate: libcgroup security update Advisory ID: SLSA-2019:2047-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-14348 -- Security Fix(es): * libcgroup: cgrulesengd creates log files with insecure permissions (CVE-2018-14348) -- SL7 x86_64 libcgroup-0.41-21.el7.i686.rpm libcgroup-tools-0.41-21.el7.x86_64.rpm libcgroup-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.i686.rpm libcgroup-pam-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.x86_64.rpm libcgroup-pam-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm - Scientific Linux Development Team . Significant libcgroup patch SLSA-2019:2047-1 for SL7, rectifying unsafe logging settings. Review essential update information.. libcgroup, log permissions, security update, SL7, cgrulesengd. . Severity: Important. LinuxSecurity.com Team
An update for libcgroup is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libcgroup security update Advisory ID: RHSA-2019:2047-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2047 Issue date: 2019-08-06 CVE Names: CVE-2018-14348 ==================================================================== 1. Summary: An update for libcgroup is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The libcgroup packages provide tools and libraries to control and monitor control groups. Security Fix(es): * libcgroup: cgrulesengd creates log files with insecure permissions (CVE-2018-14348) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to theCVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1611119 - CVE-2018-14348 libcgroup: cgrulesengd creates log files with insecure permissions 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: libcgroup-0.41-21.el7.src.rpm x86_64: libcgroup-0.41-21.el7.i686.rpm libcgroup-0.41-21.el7.x86_64.rpm libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-tools-0.41-21.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.i686.rpm libcgroup-devel-0.41-21.el7.x86_64.rpm libcgroup-pam-0.41-21.el7.i686.rpm libcgroup-pam-0.41-21.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: libcgroup-0.41-21.el7.src.rpm x86_64: libcgroup-0.41-21.el7.i686.rpm libcgroup-0.41-21.el7.x86_64.rpm libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-tools-0.41-21.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.i686.rpm libcgroup-devel-0.41-21.el7.x86_64.rpm libcgroup-pam-0.41-21.el7.i686.rpm libcgroup-pam-0.41-21.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: libcgroup-0.41-21.el7.src.rpm ppc64: libcgroup-0.41-21.el7.ppc.rpm libcgroup-0.41-21.el7.ppc64.rpm libcgroup-debuginfo-0.41-21.el7.ppc.rpm libcgroup-debuginfo-0.41-21.el7.ppc64.rpm libcgroup-tools-0.41-21.el7.ppc64.rpm ppc64le: libcgroup-0.41-21.el7.ppc64le.rpm libcgroup-debuginfo-0.41-21.el7.ppc64le.rpm libcgroup-tools-0.41-21.el7.ppc64le.rpm s390x: libcgroup-0.41-21.el7.s390.rpm libcgroup-0.41-21.el7.s390x.rpm libcgroup-debuginfo-0.41-21.el7.s390.rpm libcgroup-debuginfo-0.41-21.el7.s390x.rpm libcgroup-tools-0.41-21.el7.s390x.rpm x86_64: libcgroup-0.41-21.el7.i686.rpm libcgroup-0.41-21.el7.x86_64.rpm libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-tools-0.41-21.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: libcgroup-debuginfo-0.41-21.el7.ppc.rpm libcgroup-debuginfo-0.41-21.el7.ppc64.rpm libcgroup-devel-0.41-21.el7.ppc.rpm libcgroup-devel-0.41-21.el7.ppc64.rpm libcgroup-pam-0.41-21.el7.ppc.rpm libcgroup-pam-0.41-21.el7.ppc64.rpm ppc64le: libcgroup-debuginfo-0.41-21.el7.ppc64le.rpm libcgroup-devel-0.41-21.el7.ppc64le.rpm libcgroup-pam-0.41-21.el7.ppc64le.rpm s390x: libcgroup-debuginfo-0.41-21.el7.s390.rpm libcgroup-debuginfo-0.41-21.el7.s390x.rpm libcgroup-devel-0.41-21.el7.s390.rpm libcgroup-devel-0.41-21.el7.s390x.rpm libcgroup-pam-0.41-21.el7.s390.rpm libcgroup-pam-0.41-21.el7.s390x.rpm x86_64: libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.i686.rpm libcgroup-devel-0.41-21.el7.x86_64.rpm libcgroup-pam-0.41-21.el7.i686.rpm libcgroup-pam-0.41-21.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: libcgroup-0.41-21.el7.src.rpm x86_64: libcgroup-0.41-21.el7.i686.rpm libcgroup-0.41-21.el7.x86_64.rpm libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-tools-0.41-21.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): x86_64: libcgroup-debuginfo-0.41-21.el7.i686.rpm libcgroup-debuginfo-0.41-21.el7.x86_64.rpm libcgroup-devel-0.41-21.el7.i686.rpm libcgroup-devel-0.41-21.el7.x86_64.rpm libcgroup-pam-0.41-21.el7.i686.rpm libcgroup-pam-0.41-21.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-14348 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html-single/7.7_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXUl3mdzjgjWX9erEAQiXEhAAkq5aiLsf23WX0YVPJ5dYFaghPR6zUlkF PCWw4kb6hXm62JwndHb0gJjarxBKAR6pDTjnovEQ8Go7AR7plpGQtQS+gLNTRTgj HpTW0yvW1jfrY3z4Dx6BO5FYQ9/MwgEsedUV9ub1VYz4DbR86M+p5JTZd1nsKvEH 5TuWaodPRKth9PWBNl9tqsuYLjFnwVT2D28JmOIhCyuirb5u3Pj25AwMKb2WPsTM Qj8wB7D1WB4e6CSbU61CtvefHbFg9TfQ6zE4hJe3Ki0dM08GFebdWs+Yq/MM49Ma FeQ/FOkLkHDAHIUvhiJYhYEQmwrbM71VLtd10yPjy3wewzty9ix8W1CfDC68U8QX hirgnosl5IoEoQXRRF5wtvdgJkpBOpzlAPtic9PesK7AOOIRnJ6GggnQYJyHeA6U BwTt6eY3BRZcbqnkzf56noFuRhrz9L8wXeHMd07UiM71+64JvqRa2ME5mWvikqHv 2xC193S2HcffaLCRvNOhK6U8wM7zFcoVooF6vfuR5P635Mz5wsE/0fXPbESVQgx3 kNbUZxMxzHAalJUs1TgOxlgwBqtQstwUigKU6FECqig/3s3eQFzrvaREHR8joqb5 n578bp37UO0AmWfQtZHZz+bQaNpuadakQ6M53FV8z2bFa5WgrJOMwfQL7biW8uu2 yJRQFo11TLc=FyUs -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libcgroup ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2468-1 Rating: moderate References: #1100365 Cross-References: CVE-2018-14348 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Desktop 12-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libcgroup fixes the following issues: Security issue fixed: - CVE-2018-14348: Fix daemon that creates /var/log/cgred with mode 0666 (bsc#1100365). This updates also sets the permissions of already existing log files to proper values. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-1732=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2018-1732=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2018-1732=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libcgroup-debugsource-0.41.rc1-10.9.1 libcgroup-devel-0.41.rc1-10.9.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): libcgroup-debugsource-0.41.rc1-10.9.1 libcgroup-tools-0.41.rc1-10.9.1 libcgroup-tools-debuginfo-0.41.rc1-10.9.1 libcgroup1-0.41.rc1-10.9.1 libcgroup1-debuginfo-0.41.rc1-10.9.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libcgroup-debugsource-0.41.rc1-10.9.1 libcgroup1-0.41.rc1-10.9.1 libcgroup1-debuginfo-0.41.rc1-10.9.1 References: https://www.suse.com/security/cve/CVE-2018-14348.html https://bugzilla.suse.com/1100365 . Ubuntu Security Notice regarding libcgroup mitigates risk related to log access permissions. Remediate CVE-2021-34527 promptly.. SUSE Linux libcgroup update, moderate risk, log permissions, security patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libcgroup ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2241-1 Rating: moderate References: #1100365 Cross-References: CVE-2018-14348 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libcgroup fixes the following issues: The following security vulnerability was fixed: - CVE-2018-14348: Fixed a permission issue with /var/log/cgred. The permissions were not restrictive enough beforehand and ignored any umask setting. (boo#1100365) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-821=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): libcgroup-debugsource-0.41-8.3.1 libcgroup-devel-0.41-8.3.1 libcgroup-tools-0.41-8.3.1 libcgroup-tools-debuginfo-0.41-8.3.1 libcgroup1-0.41-8.3.1 libcgroup1-debuginfo-0.41-8.3.1 - openSUSE Leap 42.3 (x86_64): libcgroup1-32bit-0.41-8.3.1 libcgroup1-debuginfo-32bit-0.41-8.3.1 References: https://www.suse.com/security/cve/CVE-2018-14348.html https://bugzilla.suse.com/1100365 -- . openSUSE Security Update: Security update for libcgroup ____________________________________________. update, security, fixes, vulnerability, opensuse. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libcgroup ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2143-1 Rating: moderate References: #1100365 Cross-References: CVE-2018-14348 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Desktop 12-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libcgroup fixes the following issues: Security issue fixed: - CVE-2018-14348: Fix daemon that creates /var/log/cgred with mode 0666 (bsc#1100365). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-1453=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2018-1453=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2018-1453=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libcgroup-debugsource-0.41.rc1-10.3.1 libcgroup-devel-0.41.rc1-10.3.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): libcgroup-debugsource-0.41.rc1-10.3.1 libcgroup-tools-0.41.rc1-10.3.1 libcgroup-tools-debuginfo-0.41.rc1-10.3.1 libcgroup1-0.41.rc1-10.3.1 libcgroup1-debuginfo-0.41.rc1-10.3.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libcgroup-debugsource-0.41.rc1-10.3.1 libcgroup1-0.41.rc1-10.3.1 libcgroup1-debuginfo-0.41.rc1-10.3.1 References: https://www.suse.com/security/cve/CVE-2018-14348.html https://bugzilla.suse.com/1100365 . An important security enhancement for libcgroup in SUSE Linux Enterprise has been announced, along with detailed guidance on how to apply the patches.. SUSE Linux Enterprise, libcgroup security, software update, moderate severity, vulnerability fix. . LinuxSecurity.com Team
Several issues have been discovered in libcgroup, a library to control and monitor control groups: CVE-2011-1006 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2193-1
Important: libcgroup security update. Date: Fri, 4 Mar 2011 15:33:09 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Important: libcgroup on SL6.x i386/x86_64 Comments: To: "
Get the latest Linux and open source security news straight to your inbox.