USN-875-1: Red Hat Cluster Suite vulnerabilities


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) USN-875-1: Red Hat Cluster Suite vulnerabilities
# 1  
Old 12-18-2009
USN-875-1: Red Hat Cluster Suite vulnerabilities

Referenced CVEs:
CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552, CVE-2008-6560


Description:
===========================================================Ubuntu Security Notice USN-875-1 December 18, 2009redhat-cluster, redhat-cluster-suite vulnerabilitiesCVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552,CVE-2008-6560===========================================================A security issue affects the following Ubuntu releases:Ubuntu 6.06 LTSUbuntu 8.04 LTSUbuntu 8.10This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 6.06 LTS: ccs 1.20060222-0ubuntu6.3 cman 1.20060222-0ubuntu6.3 fence 1.20060222-0ubuntu6.3 libcman1 1.20060222-0ubuntu6.3 rgmanager 1.20060222-0ubuntu6.3Ubuntu 8.04 LTS: cman 2.20080227-0ubuntu1.3 gfs2-tools 2.20080227-0ubuntu1.3 rgmanager 2.20080227-0ubuntu1.3Ubuntu 8.10: cman 2.20080826-0ubuntu1.3 gfs2-tools 2.20080826-0ubuntu1.3 rgmanager 2.20080826-0ubuntu1.3In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:Multiple insecure temporary file handling vulnerabilities were discoveredin Red Hat Cluster. A local attacker could exploit these to overwritearbitrary local files via symlinks. (CVE-2008-4192, CVE-2008-4579,CVE-2008-4580, CVE-2008-6552)It was discovered that CMAN did not properly handle malformed configurationfiles. An attacker could cause a denial of service (via CPU consumption andmemory corruption) in a node if the attacker were able to modify thecluster configuration for the node. (CVE-2008-6560)





More...
Login or Register to Ask a Question

Previous Thread | Next Thread

8 More Discussions You Might Find Interesting

1. Red Hat

Red Hat High Availability (HA) Cluster

How can we implement a service in HA, which in not available in HA. like sldap or customize application. Requirement Details. NODE1 service slapd is running.(Require) NODE2 service slapd is running.(Require) on both the node replication is happening. Now here requirement is need... (2 Replies)
Discussion started by: Priy
2 Replies

2. UNIX and Linux Applications

Configuration of Linux cluster managment on Red Hat 5.x server

Hi Experts, I have question regarding linux cluster managment on Red Hat 5.x server. When I try to install 'luci' or 'ricci' in one of our linux servers it is giving me below error:- yum install luci Loaded plugins: katello, product-id, rhnplugin, security, subscription-manager Updating... (0 Replies)
Discussion started by: Amey Joshi
0 Replies

3. Red Hat

Red Hat Cluster Luci Authentication Failed

Hello everyone, I'm setting up a cluster with 2 nodes using Red Hat enterprise 6.2 x86_64, 1 luci and 1 ricci for education purpose. Ricci is installed and already running and luci is installed and running but at the time of add and create the cluster through the web gui it give me a error... (1 Reply)
Discussion started by: typeav
1 Replies

4. Red Hat

Free Cluster software with Red Hat Linux 5.0

Hi, I would like to know wheather any free cluster software is coming with Red Hat Ent Linux Medias? or needs to be purchased seperately. (3 Replies)
Discussion started by: manoj.solaris
3 Replies

5. Linux

Red Hat cluster

hi... I'm new to clustering concept, there was a issue in redhat clustering as "unable to load cluster.xml no such file or directory".. this issue restrict me from starting the cluster services and too execution of clustat command .. myself using vmware work station for the cluster setup with... (4 Replies)
Discussion started by: sriniv666
4 Replies

6. Red Hat

Custom HA agent - Red Hat Linux Cluster

Hi experts, I have some custom application which I need to make Highly Available using red hat cluster service. How do I do it? i know in /usr/share/cluster i shall find HA agents for well known services like Apache or Sybase but I want to write HA agent for my own. I tried looking up on... (4 Replies)
Discussion started by: pshaikh
4 Replies

7. Red Hat

Cluster Suite IP-Aliasing

Hi, is it normal, that the IP alias (service IP) can't be seen with ifconfig -a , as eth0:1 for example the IP is on the node, you can ping it, and open ports for that IP look at this: # ip addr 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue link/loopback... (4 Replies)
Discussion started by: funksen
4 Replies

8. Red Hat

The Red Hat Cluster Manager Installation and

Linux RedHat Cluster Manager InstallationAdministrationGuide (0 Replies)
Discussion started by: merlin
0 Replies
Login or Register to Ask a Question