Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-6316

Опубликовано: 12 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-6316: pcs (LOW)

[0.11.6-3]

  • Refreshing any page in pcs-web-ui no longer causes it to display a blank page
  • Resolves: rhbz#2222788

[0.11.6-2]

  • Added BuildRequires: debugedit - for generating MiniDebugInfo - triggered by removing find-debuginfo.sh from rpm
  • Make use of filters when extracting tarballs to enhance security if provided by Python (pcs config restore command)
  • Exporting constraints with rules in form of pcs commands now escapes # and fixes spaces in dates to make the commands valid
  • Constraints containing options unsupported by pcs are not exported and a warning is printed instead
  • Using spaces in dates in location constraint rules is deprecated
  • Resolves: rhbz#2163953 rhbz#2216434 rhbz#2217850 rhbz#2219407

[0.11.6-1]

  • Rebased to the latest upstream sources (see CHANGELOG.md)
  • Updated bundled rubygems: puma, tilt
  • Resolves: rhbz#1465829 rhbz#2163440 rhbz#2168155

[0.11.5-2]

  • Fixed a regression causing crash in pcs resource move command (broken since pcs-0.11.5)
  • Resolves: rhbz#2210855

[0.11.5-1]

  • Rebased to the latest upstream sources (see CHANGELOG.md)
  • Updated pcs-web-ui
  • Updated bundled dependencies: tornado, dacite
  • Added bundled rubygems: nio4r, puma
  • Removed bundled rubygems: daemons, eventmachine, thin, webrick
  • Updated bundled rubygems: backports, rack, rack-protection, rack-test, sinatra, tilt
  • Added dependency nss-tools - for working with qdevice certificates
  • Resolves: rhbz#1423473 rhbz#1860626 rhbz#2160664 rhbz#2163440 rhbz#2163914 rhbz#2163953 rhbz#2168155 rhbz#2168617 rhbz#2174735 rhbz#2174829 rhbz#2175881 rhbz#2177996 rhbz#2178701 rhbz#2178714 rhbz#2179902 rhbz#2180379 rhbz#2182810

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

pcs

0.11.6-3.el9

pcs-snmp

0.11.6-3.el9

Oracle Linux x86_64

pcs

0.11.6-3.el9

pcs-snmp

0.11.6-3.el9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.

CVSS3: 7.5
nvd
больше 2 лет назад

decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.

CVSS3: 7.5
github
больше 2 лет назад

decode-uri-component vulnerable to Denial of Service (DoS)

CVSS3: 7.5
fstec
почти 3 года назад

Уязвимость функции decodeComponents() декодера URI компонентов decode-uri-component, позволяющая нарушителю вызвать отказ в обслуживании

oracle-oval
около 2 лет назад

ELSA-2023-1743: nodejs:14 security, bug fix, and enhancement update (IMPORTANT)