keepalived-1.3.5-16.el7
エラータID: AXSA:2019-4318:03
The keepalived utility provides simple and robust facilities for load balancing and high availability. The load balancing framework relies on the well-known and widely used IP Virtual Server (IPVS) kernel module providing layer-4 (transport layer) load balancing. Keepalived implements a set of checkers to dynamically and adaptively maintain and manage a load balanced server pool according to the health of the servers. Keepalived also implements the Virtual Router Redundancy Protocol (VRRPv2) to achieve high availability with director failover.
Security Fix(es):
* keepalived: Improper pathname validation allows for overwrite of arbitrary filenames via symlinks (CVE-2018-19044)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Asianux Server 7.7 Release Notes linked from the References section.
CVE-2018-19044
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.
Update packages.
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.
N/A
SRPMS
- keepalived-1.3.5-16.el7.src.rpm
MD5: 78283cd0aa40dac038abf5a6fb755c63
SHA-256: 5bf0d4859343a59d82b751e3804915904e4625c55d934de8b904830b8af3230f
Size: 717.66 kB
Asianux Server 7 for x86_64
- keepalived-1.3.5-16.el7.x86_64.rpm
MD5: a7e343ce66bcf571ea7a54d139e52073
SHA-256: 52ec62b67d0e32c2a3e99853c0a658ced3d23e4f1b52c2e572fb1b0cfcfc1d0a
Size: 330.49 kB