luci-0.26.0-48.AXS4

エラータID: AXSA:2014-025:01

Release date: 
Tuesday, March 11, 2014 - 13:01
Subject: 
luci-0.26.0-48.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

The luci packages contain a web-based high-availability cluster configuration application.

Security issues fixed with this release:

• CVE-2013-4481
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

• CVE-2013-4482
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.

Fixed bugs:

• Luci's capability to work with the full set of agents parameters has been restored. Configured fence device parameters that were previously discarded now work as expected: this includes parameters for "cmd_prompt", "login_timeout", "power_timeout", "retry_on", "shell_timeout" and "delay".

• Luci's capability to work with the full set of fence devices. Previously, Dell iDRAC (idrac), HP iLO2 (ilo2), HP iLO3 (ilo3), and IBM Integrated Management Module (imm) devices or agents would not properly work, nor would a cluster comprising them.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. luci-0.26.0-48.AXS4.src.rpm
    MD5: 40b030d14dde7c9464a693625584ac98
    SHA-256: d8baa005c252b515a70c759b82f020debd2aac4ff337f2b8408d6889734ef437
    Size: 472.61 kB

Asianux Server 4 for x86
  1. luci-0.26.0-48.AXS4.i686.rpm
    MD5: 0246d7e50b74708610c670dbb8009b56
    SHA-256: 15f9c0ce34055959b969c5005a810d0fbb6da91366a1699ad6ff1f48f1ab0026
    Size: 554.56 kB

Asianux Server 4 for x86_64
  1. luci-0.26.0-48.AXS4.x86_64.rpm
    MD5: 129f7966ef6bbb44918ffa2a688452c1
    SHA-256: 63474ce9e531c3ebddfff2c6218417524d9208e17b04ae0333ef963f6f27f6f5
    Size: 554.31 kB