Update to 3.3.7 - CVE-2024-47533. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-76d8603c78 2024-11-26 04:38:12.122771+00:00 -------------------------------------------------------------------------------- Name : cobbler Product : Fedora 40 Version : 3.3.7 Release : 1.fc40 URL : https://cobbler.github.io/ Summary : Boot server configurator Description : Cobbler is a network install server. Cobbler supports PXE, ISO virtualized installs, and re-installing existing Linux machines. The last two modes use a helper tool, 'koan', that integrates with cobbler. Cobbler's advanced features include importing distributions from DVDs and rsync mirrors, kickstart templating, integrated yum mirroring, and built-in DHCP/DNS Management. Cobbler has a XML-RPC API for integration with other applications. -------------------------------------------------------------------------------- Update Information: Update to 3.3.7 - CVE-2024-47533 -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 17 2024 Orion Poplawski - 3.3.7-1 - Update to 3.3.7 (CVE-2024-47533) * Fri Sep 27 2024 Carl George - 3.3.6-2 - Fix cheetah dependency rhbz#2314630 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2326874 - cobbler-3.3.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2326874 [ 2 ] Bug #2327081 - CVE-2024-47533 cobbler: Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2327081 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-76d8603c78' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix for CVE-2022-0860. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-224e71968f 2022-03-27 00:15:22.650965 --------------------------------------------------------------------------------Name : cobbler Product : Fedora 36 Version : 3.3.2 Release : 1.fc36 URL : https://cobbler.github.io/ Summary : Boot server configurator Description : Cobbler is a network install server. Cobbler supports PXE, ISO virtualized installs, and re-installing existing Linux machines. The last two modes use a helper tool, 'koan', that integrates with cobbler. Cobbler's advanced features include importing distributions from DVDs and rsync mirrors, kickstart templating, integrated yum mirroring, and built-in DHCP/DNS Management. Cobbler has a XML-RPC API for integration with other applications. --------------------------------------------------------------------------------Update Information: Fix for CVE-2022-0860 --------------------------------------------------------------------------------ChangeLog: * Sat Mar 12 2022 Orion Poplawski - 3.3.2-1 - Update to 3.3.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2066593 - CVE-2022-0860 cobbler: Improper Authorization in cobbler [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2066593 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-224e71968f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for cobbler is now available for Red Hat Satellite 5.6, Red Hat Satellite 5.7, and Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: cobbler security update Advisory ID: RHSA-2018:2372-01 Product: Red Hat Satellite Advisory URL: https://access.redhat.com/errata/RHSA-2018:2372 Issue date: 2018-08-09 CVE Names: CVE-2018-10931 ==================================================================== 1. Summary: An update for cobbler is now available for Red Hat Satellite 5.6, Red Hat Satellite 5.7, and Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Satellite 5.6 (RHEL v.6) - noarch Red Hat Satellite 5.7 (RHEL v.6) - noarch Red Hat Satellite 5.8 (RHEL v.6) - noarch 3. Description: Cobbler is a network install server. Cobbler supports PXE, virtualized installs, and re-installing existing Linux machines. Cobbler has a XMLRPC API for integration with other applications. Security Fix(es): * cobbler: CobblerXMLRPCInterface exports all its methods over XMLRPC (CVE-2018-10931) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. This issue was discovered by Cedric Buissart (Red Hat). 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For thisupdate to take effect, Red Hat Satellite must be restarted ("/usr/sbin/rhn-satellite restart"). 5. Bugs fixed (https://bugzilla.redhat.com/): 1613861 - CVE-2018-10931 cobbler: CobblerXMLRPCInterface exports all its methods over XMLRPC 6. Package List: Red Hat Satellite 5.6 (RHEL v.6): Source: cobbler-2.0.7-44.1.el6sat.src.rpm noarch: cobbler-2.0.7-44.1.el6sat.noarch.rpm Red Hat Satellite 5.7 (RHEL v.6): Source: cobbler-2.0.7-68.1.el6sat.src.rpm noarch: cobbler-2.0.7-68.1.el6sat.noarch.rpm Red Hat Satellite 5.8 (RHEL v.6): Source: cobbler-2.0.7-73.el6sat.src.rpm noarch: cobbler-2.0.7-73.el6sat.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-10931 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW2xhhtzjgjWX9erEAQjRpw//SYOhtx/D0hGMUE7fbFM1LKtVWy3vCdBf NV4fZ/3QcRHalxMNLag2oOenP9ywWpP167b47QUUGMKbT53EL6ETh5luS6PEJWMu dYQuMV94yJpk9JlZh53/7MuTuBcgpWtwA3l1XXHnbP2nPNvlcD/PlCASNCnZCQkA eQka02gjhWHNgscqhTdRKxFPzTn0Ql14jMI4n+eiXBpMuzX01kX1fn5STyOQztRI DuMFX4ZJKS8kmInkv4OOgfycu/mjHgPUtc2Tx0p3HSKpgI9Kdn2cb8+lQi5aFVro VUYkx28rSXDeCmK6Jo6Szbnu0PheYSt0mbYIX7i6H6tKkb9IWCFLcoZwGfvjmfYO jFSksbr4lz91vi6wpr46TtmHVN0Yi9KbrW2+jLpbiMW3bbp7lRPZLEUpiWQiXKOc t7yvh09jNJStKAtnJ7koh1oiggA3/RaCtc8tw+a+pDCuLE0IH8oBSNuWxE4ySCtv P2BxJbAAER40fhJZzA1COa0P4j9okmatjgQ6zf4ySoNQpMPOmqRSOE6mGPDwO2G2 g11DAHFM2lL5FvWwlQyAHsikJ3+HyYc9asqvdLqwGjsbOfgSIN+BDVmG9M+X9NjD 0lu0greZq7GBLT7/di5rOP097D9BkKY9A0z2plXNpr0/5BYBYEgXqaxCH3WKQDap Y85n6ujcKso=hix/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.