Low: selinux-policy enhancement update. Date: Thu, 8 Mar 2012 14:46:20 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Low: selinux-policy on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: selinux-policy enhancement update Issue date: 2012-03-07 This update fixes the following bugs: * An incorrect SELinux policy prevented the qpidd service from connecting to the AMQP (Advanced Message Queuing Protocol) port when the qpidd daemon was configured with Corosync clustering. These selinux-policy packages contain updated SELinux rules, which allow the qpidd service to be started correctly. * With SELinux in enforcing mode, an OpenMPI job submitted to the parallel universe environment failed on ssh keys generation. This happened because the ssh-keygen utility was not able to read from and write to the "/var/lib/condor/" directory". With this update, a new SELinux policy has been added for the "/var/lib/condor/" directory, which allows the ssh-keygen utility to read from and write to this directory.SL6.x SRPMS: selinux-policy-3.7.19-126.el6_2.10.src.rpm i386: selinux-policy-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.10.noarch.rpm x86_64: selinux-policy-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.10.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.10.noarch.rpm . SELinux configuration revised to resolve connectivity problems and access rights for OpenMPI tasks in Scientific Linux.. SELinux Policy Update, Scientific Linux Security, AMQP Service Fix. . Severity: Low. LinuxSecurity.com Team
An error condition can cause D-Bus to crash.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200901-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: D-Bus: Denial of Service Date: January 11, 2009 Bugs: #240308 ID: 200901-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An error condition can cause D-Bus to crash. Background ========= D-Bus is a daemon providing a framework for applications to communicate with one another. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/dbus < 1.2.3-r1 > = 1.2.3-r1 Description ========== schelte reported that the dbus_signature_validate() function can trigger a failed assertion when processing a message containing a malformed signature. Impact ===== A local user could send a specially crafted message to the D-Bus daemon, leading to a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All D-Bus users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/dbus-1.2.3-r1" References ========= [ 1 ] CVE-2008-3834 https://www.cve.org/CVERecord?id=CVE-2008-3834 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200901-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is ofutmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.