Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0779-1

Опубликовано: 24 мар. 2020
Источник: suse-cvrf

Описание

Security update for keepalived

This update for keepalived fixes the following issues:

Initial release of keepalived v2.0.19 as supported package. (bsc#1158280, jsc#ECO-223)

Список пакетов

Container ses/7.1/ceph/keepalived:latest
keepalived-2.0.19-3.3.1
SUSE Linux Enterprise High Availability Extension 15 SP1
keepalived-2.0.19-3.3.1

Описание

keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.


Затронутые продукты
Container ses/7.1/ceph/keepalived:latest:keepalived-2.0.19-3.3.1
SUSE Linux Enterprise High Availability Extension 15 SP1:keepalived-2.0.19-3.3.1

Ссылки

Описание

keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.


Затронутые продукты
Container ses/7.1/ceph/keepalived:latest:keepalived-2.0.19-3.3.1
SUSE Linux Enterprise High Availability Extension 15 SP1:keepalived-2.0.19-3.3.1

Ссылки

Описание

keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the keepalived process, then this potentially leaked sensitive information.


Затронутые продукты
Container ses/7.1/ceph/keepalived:latest:keepalived-2.0.19-3.3.1
SUSE Linux Enterprise High Availability Extension 15 SP1:keepalived-2.0.19-3.3.1

Ссылки