Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
- Security fix for CVE-2017-2661: Improper node name field validation when creating clusters leads to XSS - Re-added support for clufter as it is now available for Python 3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-71e69a691b 2017-04-03 16:06:19.908858 -------------------------------------------------------------------------------- Name : pcs Product : Fedora 25 Version : 0.9.156 Release : 2.fc25 URL : https://github.com/ClusterLabs/pcs Summary : Pacemaker Configuration System Description : pcs is a corosync and pacemaker configuration tool. It permits users to easily view, modify and create pacemaker based clusters. -------------------------------------------------------------------------------- Update Information: - Security fix for CVE-2017-2661: Improper node name field validation when creating clusters leads to XSS - Re-added support for clufter as it is now available for Python 3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1428948 - CVE-2017-2661 pcs: Improper node name field validation when creating clusters leads to XSS https://bugzilla.redhat.com/show_bug.cgi?id=1428948 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade pcs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.