Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-1930

Опубликовано: 17 мая 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-1930: keepalived security and bug fix update (MODERATE)

[2.1.5-8]

  • Fix DBus policy restrictions (#2028350, CVE-2021-44225)

[2.1.5-7]

  • Fix log-facility option (#197716)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

keepalived

2.1.5-8.el8

Oracle Linux x86_64

keepalived

2.1.5-8.el8

Связанные CVE

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 3 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 7.5
redhat
больше 3 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 5.4
nvd
больше 3 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 5.4
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.4
debian
больше 3 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently re ...