USN-875-1: Red Hat Cluster Suite vulnerabilities

view full story

http://www.ubuntu.com – Referenced CVEs:  CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552, CVE-2008-6560 Description:  =========================================================== Ubuntu Security Notice USN-875-1 December 18, 2009 redhat-cluster, redhat-cluster-suite vulnerabilities CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552, CVE-2008-6560 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: ccs 1.20060222-0ubuntu6.3 cman 1.20060222-0ubuntu6.3 fence 1.20060222-0ubuntu6.3 libcman1 1.20060222-0ubuntu6.3 rgmanager 1.20060222-0ubuntu6.3 Ubuntu 8.04 LTS: cman 2.20080227-0ubuntu1.3 gfs2-tools 2.20080227-0ubuntu1.3 rgmanager 2.20080227-0ubuntu1.3 Ubuntu 8.10: cman 2.20080826-0ubuntu1.3 gfs2-tools 2.20080826-0ubuntu1.3 rgmanager 2.20080826-0ubuntu1.3 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Multiple insecure temporary file handling vulnerabilities were discovered in Red Hat Cluster. A local attacker could exploit these to overwrite arbitrary local files via symlinks. (CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552) It was discovered that CMAN did not properly handle malformed configuration files. An attacker could cause a denial of service (via CPU consumption and memory corruption) in a node if the attacker were able to modify the cluster configuration for the node. (CVE-2008-6560) (Distributions)