Explore top 10 tips to secure your open-source projects now. Read More
×
Security fix for CVE-2017-11610. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-85eb9f7a36 2017-08-07 13:52:29.113257 --------------------------------------------------------------------------------Name : supervisor Product : Fedora 25 Version : 3.2.4 Release : 1.fc25 URL : https://supervisord.org/ Summary : A System for Allowing the Control of Process State on UNIX Description : The supervisor is a client/server system that allows its users to control a number of processes on UNIX-like operating systems. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-11610 --------------------------------------------------------------------------------References: [ 1 ] Bug #1476144 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1476144 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade supervisor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-11610. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-713430fb15 2017-08-07 13:50:50.150551 --------------------------------------------------------------------------------Name : supervisor Product : Fedora 24 Version : 3.1.4 Release : 1.fc24 URL : https://supervisord.org/ Summary : A System for Allowing the Control of Process State on UNIX Description : The supervisor is a client/server system that allows its users to control a number of processes on UNIX-like operating systems. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-11610 --------------------------------------------------------------------------------References: [ 1 ] Bug #1476144 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1476144 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade supervisor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-11610. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-307eab89e1 2017-08-07 13:52:27.804029 --------------------------------------------------------------------------------Name : supervisor Product : Fedora 26 Version : 3.3.3 Release : 1.fc26 URL : https://supervisord.org/ Summary : A System for Allowing the Control of Process State on UNIX Description : The supervisor is a client/server system that allows its users to control a number of processes on UNIX-like operating systems. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-11610 --------------------------------------------------------------------------------References: [ 1 ] Bug #1476144 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1476144 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade supervisor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A vulnerability has been found in supervisor, a system for controlling process state, where an authenticated client can send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server. The commands will be run as the same user as supervisord. . Hash: SHA512 Package : supervisor Version : 3.0a8-1.1+deb7u2 CVE ID : CVE-2017-11610 Debian Bug : 870187 A vulnerability has been found in supervisor, a system for controlling process state, where an authenticated client can send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server. The commands will be run as the same user as supervisord. For Debian 7 "Wheezy", these problems have been fixed in version 3.0a8-1.1+deb7u2. We recommend that you upgrade your supervisor packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An exploit in supervisord permits unauthorized command execution through crafted XML-RPC requests on Debian 7.. supervisor security, debian update, arbitrary command execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.