Otkriven je sigurnosni propust u paketu bfcg kojeg mogu iskoristiti udaljeni napadači kako bi pokretali proizvoljne naredbe i tako povećali svoje ovlasti.
Paket: | bcfg 1.x |
Operacijski sustavi: | Fedora 14, Fedora 15 |
Kritičnost: | 8.1 |
Problem: | neodgovarajuća provjera ulaznih podataka |
Iskorištavanje: | udaljeno |
Posljedica: | dobivanje većih privilegija, pokretanje proizvoljnih naredbi |
Rješenje: | programska zakrpa proizvođača |
CVE: | CVE-2011-3211 |
Izvorni ID preporuke: | FEDORA-2011-12303 |
Izvor: | Fedora |
Problem: | |
Propust je uzrokovan nepravilnom obradom podataka od bcfg2 klijenata kada se koristi SSHbase dodatak. |
|
Posljedica: | |
Udaljeni napadač može iskoristiti propust za izvođenje proizvoljnih naredbi i povećanje ovlasti. |
|
Rješenje: | |
Korisnicima se savjetuje korištenje najnovije inačice. |
Izvorni tekst preporuke
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-12303
2011-09-08 06:38:47
--------------------------------------------------------------------------------
Name : bcfg2
Product : Fedora 14
Version : 1.1.2
Release : 2.fc14
URL : http://bcfg2.org
Summary : Configuration management system
Description :
Bcfg2 helps system administrators produce a consistent, reproducible,
and verifiable description of their environment, and offers
visualization and reporting tools to aid in day-to-day administrative
tasks. It is the fifth generation of configuration management tools
developed in the Mathematics and Computer Science Division of Argonne
National Laboratory.
It is based on an operational model in which the specification can be
used to validate and optionally change the state of clients, but in a
feature unique to bcfg2 the client's response to the specification can
also be used to assess the completeness of the specification. Using
this feature, bcfg2 provides an objective measure of how good a job an
administrator has done in specifying the configuration of client
systems. Bcfg2 is therefore built to help administrators construct an
accurate, comprehensive specification.
Bcfg2 has been designed from the ground up to support gentle
reconciliation between the specification and current client states. It
is designed to gracefully cope with manual system modifications.
Finally, due to the rapid pace of updates on modern networks, client
systems are constantly changing; if required in your environment,
Bcfg2 can enable the construction of complex change management and
deployment strategies.
--------------------------------------------------------------------------------
Update Information:
* Wed Sep 07 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-2
- Added patch to fix CVE-2011-3211
* Thu Jun 02 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-1
- Updated to new upstream version 1.1.2
- Fixed #683239
* Mon Sep 27 2010 Jeffrey C. Ollie <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.0-2 - Update to
final version
--------------------------------------------------------------------------------
ChangeLog:
* Wed Sep 7 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-2
- Added patch to fix CVE-2011-3211
* Thu Jun 2 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-1
- Updated to new upstream version 1.1.2
- Pooled file section entries to reduce future maintenance
- Fixed #683239
* Mon Feb 7 2011 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- 1.1.1-2.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Nov 18 2010 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.1-2
- Added new man page
- Updated doc section (ChangeLog is gone)
* Thu Nov 18 2010 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.1-1
- Updated to new upstream version 1.1.1
* Fri Nov 5 2010 Jeffrey C. Ollie <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.0-3
- Add patch from Gordon Messmer to fix authentication on F14+ (Python 2.7)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #736279 - CVE-2011-3211 bcfg2 (bcfg2-server): Privilege escalation
due to improper escaping of shell command data sent from client, when SSHbase
plug-in enabled
https://bugzilla.redhat.com/show_bug.cgi?id=736279
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update bcfg2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-12298
2011-09-08 06:38:35
--------------------------------------------------------------------------------
Name : bcfg2
Product : Fedora 15
Version : 1.1.2
Release : 2.fc15
URL : http://bcfg2.org
Summary : Configuration management system
Description :
Bcfg2 helps system administrators produce a consistent, reproducible,
and verifiable description of their environment, and offers
visualization and reporting tools to aid in day-to-day administrative
tasks. It is the fifth generation of configuration management tools
developed in the Mathematics and Computer Science Division of Argonne
National Laboratory.
It is based on an operational model in which the specification can be
used to validate and optionally change the state of clients, but in a
feature unique to bcfg2 the client's response to the specification can
also be used to assess the completeness of the specification. Using
this feature, bcfg2 provides an objective measure of how good a job an
administrator has done in specifying the configuration of client
systems. Bcfg2 is therefore built to help administrators construct an
accurate, comprehensive specification.
Bcfg2 has been designed from the ground up to support gentle
reconciliation between the specification and current client states. It
is designed to gracefully cope with manual system modifications.
Finally, due to the rapid pace of updates on modern networks, client
systems are constantly changing; if required in your environment,
Bcfg2 can enable the construction of complex change management and
deployment strategies.
--------------------------------------------------------------------------------
Update Information:
* Wed Sep 07 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-2
- Added patch to fix CVE-2011-3211
* Thu Jun 02 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-1
- Updated to new upstream version 1.1.2
- Fixed #683239
* Mon Sep 27 2010 Jeffrey C. Ollie <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.0-2 - Update to
final version
--------------------------------------------------------------------------------
ChangeLog:
* Wed Sep 7 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-2
- Added patch to fix CVE-2011-3211
* Thu Jun 2 2011 Fabian Affolter <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.1.2-1
- Updated to new upstream version 1.1.2
- Pooled file section entries to reduce future maintenance
- Fixed #683239
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #736279 - CVE-2011-3211 bcfg2 (bcfg2-server): Privilege escalation
due to improper escaping of shell command data sent from client, when SSHbase
plug-in enabled
https://bugzilla.redhat.com/show_bug.cgi?id=736279
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update bcfg2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke