Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-0597

Опубликовано: 18 мар. 2019
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2019-0597: cloud-init security update (MODERATE)

[18.2-1.0.1]

  • add modified version of enable-ec2_utils-to-stop-retrying-to-get-ec2-metadata.patch for 18.2:
    1. Enable ec2_utils.py having a way to stop retrying to get ec2 metadata
    2. Apply stop retrying to get ec2 metadata to helper/openstack.py MetadataReader Resolves: Oracle-Bug:41660 (Bugzilla)

[18.2-1.el7_6.2]

  • ci-azure-Filter-list-of-ssh-keys-pulled-from-fabric.patch [bz#1684038]
  • Resolves: bz#1684038 (EMBARGOED cloud-init: wrong list of ssh keys added to authorized_keys [rhel-7.6.z])

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

cloud-init

18.2-1.0.1.el7_6.2

Oracle Linux x86_64

cloud-init

18.2-1.0.1.el7_6.2

Связанные CVE

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

CVSS3: 5.4
redhat
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

CVSS3: 5.1
nvd
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

msrc
больше 6 лет назад

Azure SSH Keypairs Security Feature Bypass Vulnerability

CVSS3: 5.1
debian
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a chang ...