SCIENTIFIC-LINUX-ERRATA Archives

January 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Pat Riehecky <[log in to unmask]>
Date:
Wed, 16 Jan 2013 16:10:18 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (84 lines)
Synopsis:          Low: conga security, bug fix, and enhancement update
Issue Date:        2013-01-08
CVE Numbers:       CVE-2012-3359
--

It was discovered that luci stored usernames and passwords in session 
cookies.
This issue prevented the session inactivity timeout feature from working
correctly, and allowed attackers able to get access to a session cookie to
obtain the victim's authentication credentials. (CVE-2012-3359)

This update also fixes the following bugs:

* Prior to this update, luci did not allow the fence_apc_snmp agent to be
configured. As a consequence, users could not configure or view an existing
configuration for fence_apc_snmp. This update adds a new screen that allows
fence_apc_snmp to be configured.

* Prior to this update, luci did not allow the SSL operation of the 
fence_ilo
fence agent to be enabled or disabled. As a consequence, users could not
configure or view an existing configuration for the 'ssl' attribute for
fence_ilo. This update adds a checkbox to show whether the SSL operation is
enabled and allows users to edit that attribute.

* Prior to this update, luci did not allow the "identity_file" attribute 
of the
fence_ilo_mp fence agent to be viewed or edited. As a consequence, users 
could
not configure or view an existing configuration for the "identity_file"
attribute of the fence_ilo_mp fence agent. This update adds a text input 
box to
show the current state of the "identity_file" attribute of fence_ilo_mp and
allows users to edit that attribute.

* Prior to this update, redundant files and directories remained on the file
system at /var/lib/luci/var/pts and /usr/lib{,64}/luci/zope/var/pts when the
luci package was uninstalled. This update removes these files and 
directories
when the luci package is uninstalled.

* Prior to this update, the "restart-disable" recovery policy was not 
displayed
in the recovery policy list from which users could select when they 
configure a
recovery policy for a failover domain. As a consequence, the 
"restart-disable"
recovery policy could not be set with the luci GUI. This update adds the
"restart-disable" recovery option to the recovery policy pulldown list.

* Prior to this update, line breaks that were not anticipated in the 
"yum list"
output could cause package upgrade and/or installation to fail when creating
clusters or adding nodes to existing clusters. As a consequence, creating
clusters and adding cluster nodes to existing clusters could fail. This 
update
modifies the ricci daemon to be able to correctly handle line breaks in the
"yum list" output.

In addition, this update adds the following enhancements:

* This update adds support for configuring the Intel iPDU fence agent to the
luci package.

* This update adds support for viewing and changing the state of the new
'nfsrestart' attribute to the FS and Cluster FS resource agent configuration
screens.

After installing this update, the luci and ricci services will be restarted
automatically.
--

SL5
   x86_64
     conga-debuginfo-0.12.2-64.el5.x86_64.rpm
     luci-0.12.2-64.el5.x86_64.rpm
     ricci-0.12.2-64.el5.x86_64.rpm
   i386
     conga-debuginfo-0.12.2-64.el5.i386.rpm
     luci-0.12.2-64.el5.i386.rpm
     ricci-0.12.2-64.el5.i386.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2