Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1400-1

Опубликовано: 15 мая 2019
Источник: suse-cvrf

Описание

Security update for pacemaker

This update for pacemaker fixes the following issues:

Security issues fixed:

  • CVE-2019-3885: Fixed an information disclosure in log output. (bsc#1131357)
  • CVE-2018-16877: Fixed a local privilege escalation through insufficient IPC client-server authentication. (bsc#1131356)
  • CVE-2018-16878: Fixed a denial of service through insufficient verification inflicted preference of uncontrolled processes. (bsc#1131353)

Non-security issue fixed:

  • crmd: delete resource from lrmd when appropriate to avoid timeouts with crmsh (bsc#1117381).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libpacemaker-devel-1.1.18+20180430.b12c320f5-lp150.2.9.1
libpacemaker3-1.1.18+20180430.b12c320f5-lp150.2.9.1
pacemaker-1.1.18+20180430.b12c320f5-lp150.2.9.1
pacemaker-cli-1.1.18+20180430.b12c320f5-lp150.2.9.1
pacemaker-cts-1.1.18+20180430.b12c320f5-lp150.2.9.1
pacemaker-remote-1.1.18+20180430.b12c320f5-lp150.2.9.1

Описание

A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.


Затронутые продукты
openSUSE Leap 15.0:libpacemaker-devel-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:libpacemaker3-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:pacemaker-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:pacemaker-cli-1.1.18+20180430.b12c320f5-lp150.2.9.1

Ссылки

Описание

A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS


Затронутые продукты
openSUSE Leap 15.0:libpacemaker-devel-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:libpacemaker3-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:pacemaker-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:pacemaker-cli-1.1.18+20180430.b12c320f5-lp150.2.9.1

Ссылки

Описание

A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.


Затронутые продукты
openSUSE Leap 15.0:libpacemaker-devel-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:libpacemaker3-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:pacemaker-1.1.18+20180430.b12c320f5-lp150.2.9.1
openSUSE Leap 15.0:pacemaker-cli-1.1.18+20180430.b12c320f5-lp150.2.9.1

Ссылки
Уязвимость openSUSE-SU-2019:1400-1