Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1751-1

Опубликовано: 20 июл. 2019
Источник: suse-cvrf

Описание

Security update for fence-agents

This update for fence-agents version 4.4.0 fixes the following issues:

Security issue fixed:

  • CVE-2019-10153: Fixed a denial of service via guest VM comments (bsc#1137314).

Non-security issue fixed:

  • Added aliyun fence agent (bsc#1139913).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Список пакетов

openSUSE Leap 15.1
fence-agents-4.4.0+git.1558595666.5f79f9e9-lp151.2.3.1
fence-agents-amt_ws-4.4.0+git.1558595666.5f79f9e9-lp151.2.3.1
fence-agents-devel-4.4.0+git.1558595666.5f79f9e9-lp151.2.3.1

Описание

A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.


Затронутые продукты
openSUSE Leap 15.1:fence-agents-4.4.0+git.1558595666.5f79f9e9-lp151.2.3.1
openSUSE Leap 15.1:fence-agents-amt_ws-4.4.0+git.1558595666.5f79f9e9-lp151.2.3.1
openSUSE Leap 15.1:fence-agents-devel-4.4.0+git.1558595666.5f79f9e9-lp151.2.3.1

Ссылки