USN-875-1: Red Hat Cluster Suite vulnerabilities
USN-875-1: Red Hat Cluster Suite vulnerabilities
Referenced CVEs:
CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552, CVE-2008-6560
Description:
===========================================================
Ubuntu Security Notice USN-875-1 December 18, 2009
redhat-cluster, redhat-cluster-suite vulnerabilities
CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552,
CVE-2008-6560
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
ccs 1.20060222-0ubuntu6.3
cman 1.20060222-0ubuntu6.3
fence 1.20060222-0ubuntu6.3
libcman1 1.20060222-0ubuntu6.3
rgmanager 1.20060222-0ubuntu6.3
Ubuntu 8.04 LTS:
cman 2.20080227-0ubuntu1.3
gfs2-tools 2.20080227-0ubuntu1.3
rgmanager 2.20080227-0ubuntu1.3
Ubuntu 8.10:
cman 2.20080826-0ubuntu1.3
gfs2-tools 2.20080826-0ubuntu1.3
rgmanager 2.20080826-0ubuntu1.3
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Multiple insecure temporary file handling vulnerabilities were discovered
in Red Hat Cluster. A local attacker could exploit these to overwrite
arbitrary local files via symlinks. (CVE-2008-4192, CVE-2008-4579,
CVE-2008-4580, CVE-2008-6552)
It was discovered that CMAN did not properly handle malformed configuration
files. An attacker could cause a denial of service (via CPU consumption and
memory corruption) in a node if the attacker were able to modify the
cluster configuration for the node. (CVE-2008-6560)
