pcs-0.11.4-7.el9.ML.1

エラータID: AXSA:2023-6066:10

Release date: 
Friday, June 16, 2023 - 07:22
Subject: 
pcs-0.11.4-7.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

* pcs: webpack: Regression of CVE-2023-28154 fixes in the MIRACLE LINUX (CVE-2023-2319)
* rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530)
* rubygem-rack: denial of service in header parsing (CVE-2023-27539)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints
* Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources
* [WebUI] fence levels prevent loading of cluster status

CVE-2023-2319
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linux 9.2.
CVE-2023-27530
A DoS vulnerability exists in Rack <v3.0.4.2, <2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
CVE-2023-27539
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. pcs-0.11.4-7.el9.ML.1.src.rpm
    MD5: c2eecfb18cd880a9dbc8e05e5efac2e0
    SHA-256: 250fa319d6ff3f3ac3fe1c6bf47d5f1a4a518b67486fb71b3452e80680709146
    Size: 51.81 MB

Asianux Server 9 for x86_64
  1. pcs-0.11.4-7.el9.ML.1.x86_64.rpm
    MD5: aab3c77fa68cb0f1df059a631bd7f8e2
    SHA-256: 101dd9157bfc8bbf9cdc9169a1699be331e43e071e65694aae06ca2a5037cb17
    Size: 7.88 MB
  2. pcs-snmp-0.11.4-7.el9.ML.1.x86_64.rpm
    MD5: f3b4e65299aa914bca0f93bda398336e
    SHA-256: 240c5fd2fb0df8677693ba74f326e45102e17ab113408b4ceb6dc5104102d128
    Size: 62.45 kB