keepalived-1.3.5-16.el7

エラータID: AXSA:2019-4318:03

Release date: 
Wednesday, September 25, 2019 - 08:23
Subject: 
keepalived-1.3.5-16.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

The keepalived utility provides simple and robust facilities for load balancing and high availability. The load balancing framework relies on the well-known and widely used IP Virtual Server (IPVS) kernel module providing layer-4 (transport layer) load balancing. Keepalived implements a set of checkers to dynamically and adaptively maintain and manage a load balanced server pool according to the health of the servers. Keepalived also implements the Virtual Router Redundancy Protocol (VRRPv2) to achieve high availability with director failover.

Security Fix(es):

* keepalived: Improper pathname validation allows for overwrite of arbitrary filenames via symlinks (CVE-2018-19044)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 7.7 Release Notes linked from the References section.

CVE-2018-19044
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. keepalived-1.3.5-16.el7.src.rpm
    MD5: 78283cd0aa40dac038abf5a6fb755c63
    SHA-256: 5bf0d4859343a59d82b751e3804915904e4625c55d934de8b904830b8af3230f
    Size: 717.66 kB

Asianux Server 7 for x86_64
  1. keepalived-1.3.5-16.el7.x86_64.rpm
    MD5: a7e343ce66bcf571ea7a54d139e52073
    SHA-256: 52ec62b67d0e32c2a3e99853c0a658ced3d23e4f1b52c2e572fb1b0cfcfc1d0a
    Size: 330.49 kB