Описание
Security update for fence-agents
This update for fence-agents version 4.4.0 fixes the following issues:
Security issue fixed:
- CVE-2019-10153: Fixed a denial of service via guest VM comments (bsc#1137314).
Non-security issue fixed:
- Included timestamps when logging (bsc#1049852).
Список пакетов
SUSE Linux Enterprise High Availability Extension 15
fence-agents-4.4.0+git.1558595666.5f79f9e9-4.6.1
fence-agents-devel-4.4.0+git.1558595666.5f79f9e9-4.6.1
Ссылки
- Link for SUSE-SU-2019:1813-1
- E-Mail link for SUSE-SU-2019:1813-1
- SUSE Security Ratings
- SUSE Bug 1049852
- SUSE Bug 1137314
- SUSE CVE CVE-2019-10153 page
Описание
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.
Затронутые продукты
SUSE Linux Enterprise High Availability Extension 15:fence-agents-4.4.0+git.1558595666.5f79f9e9-4.6.1
SUSE Linux Enterprise High Availability Extension 15:fence-agents-devel-4.4.0+git.1558595666.5f79f9e9-4.6.1
Ссылки
- CVE-2019-10153
- SUSE Bug 1137314