SCIENTIFIC-LINUX-ERRATA Archives

March 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Pat Riehecky <[log in to unmask]>
Date:
Mon, 4 Mar 2013 13:09:34 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (133 lines)
Synopsis:          Critical: openafs security update
Issue Date:        2013-03-04
CVE Numbers:       CVE-2013-1794
                    CVE-2013-1795
--

By carefully crafting an ACL entry an attacker may overflow fixed
length buffers within the OpenAFS fileserver, crashing the fileserver,
and potentially permitting the execution of arbitrary code. To perform
the exploit, the attacker must already have permissions to create ACLs
on the fileserver in question. Once such an ACL is present on a
fileserver, client utilities such as 'fs' which manipulate ACLs, may be
crashed when they attempt to read or modify the ACL.(CVE-2013-1794)

The ptserver accepts a list of unbounded size from the IdToName RPC.
The length of this list is then used to determine the size of a number
of other internal data structures. If the length is sufficiently large
then we may hit an integer overflow when calculating the size to pass
to malloc, and allocate data structures of insufficient length,
allowing heap memory to be overwritten.  This may allow an
unauthenticated attacker to crash an OpenAFS ptserver. (CVE-2013-1795)

Scientific Linux 5 users must also update to at least
kernel-2.6.18-308.20.1.el5 to receive a compatible kernel module.

Scientific Linux 6 users must also update to at least
kernel-2.6.32-279.el6 to avoid issues with system stability.
Any 32-bit SL6 system should be aware of possible problems with the
afs cache when switching from kernels prior to kernel-2.6.32-279.el6.
Purging your OpenAFS cache seems to resolve this issue.

After installing the update, OpenAFS services must be restarted for the 
changes to take effect.
--

SL5
   x86_64
kernel-module-openafs-2.6.18-308.20.1.el5-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-308.20.1.el5-debuginfo-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-308.20.1.el5xen-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-308.20.1.el5xen-debuginfo-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-308.24.1.el5-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-308.24.1.el5-debuginfo-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-308.24.1.el5xen-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-308.24.1.el5xen-debuginfo-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-348.1.1.el5-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-348.1.1.el5-debuginfo-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-348.1.1.el5xen-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-348.1.1.el5xen-debuginfo-1.4.14-82.sl5.x86_64.rpm
     kernel-module-openafs-2.6.18-348.el5-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-348.el5-debuginfo-1.4.14-82.sl5.x86_64.rpm
     kernel-module-openafs-2.6.18-348.el5xen-1.4.14-82.sl5.x86_64.rpm
kernel-module-openafs-2.6.18-348.el5xen-debuginfo-1.4.14-82.sl5.x86_64.rpm
     openafs-1.4.14-82.sl5.x86_64.rpm
     openafs-authlibs-1.4.14-82.sl5.x86_64.rpm
     openafs-authlibs-devel-1.4.14-82.sl5.x86_64.rpm
     openafs-client-1.4.14-82.sl5.x86_64.rpm
     openafs-compat-1.4.14-82.sl5.x86_64.rpm
     openafs-debug-1.4.14-82.sl5.x86_64.rpm
     openafs-debuginfo-1.4.14-82.sl5.x86_64.rpm
     openafs-devel-1.4.14-82.sl5.x86_64.rpm
     openafs-kernel-source-1.4.14-82.sl5.x86_64.rpm
     openafs-kpasswd-1.4.14-82.sl5.x86_64.rpm
     openafs-krb5-1.4.14-82.sl5.x86_64.rpm
     openafs-server-1.4.14-82.sl5.x86_64.rpm

   i386
     kernel-module-openafs-2.6.18-308.20.1.el5-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.20.1.el5-debuginfo-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.20.1.el5PAE-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.20.1.el5PAE-debuginfo-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.20.1.el5xen-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.20.1.el5xen-debuginfo-1.4.14-82.sl5.i686.rpm
     kernel-module-openafs-2.6.18-308.24.1.el5-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.24.1.el5-debuginfo-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.24.1.el5PAE-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.24.1.el5PAE-debuginfo-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.24.1.el5xen-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-308.24.1.el5xen-debuginfo-1.4.14-82.sl5.i686.rpm
     kernel-module-openafs-2.6.18-348.1.1.el5-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.1.1.el5-debuginfo-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.1.1.el5PAE-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.1.1.el5PAE-debuginfo-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.1.1.el5xen-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.1.1.el5xen-debuginfo-1.4.14-82.sl5.i686.rpm
     kernel-module-openafs-2.6.18-348.el5-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.el5-debuginfo-1.4.14-82.sl5.i686.rpm
     kernel-module-openafs-2.6.18-348.el5PAE-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.el5PAE-debuginfo-1.4.14-82.sl5.i686.rpm
     kernel-module-openafs-2.6.18-348.el5xen-1.4.14-82.sl5.i686.rpm
kernel-module-openafs-2.6.18-348.el5xen-debuginfo-1.4.14-82.sl5.i686.rpm
     openafs-1.4.14-82.sl5.i686.rpm
     openafs-authlibs-1.4.14-82.sl5.i686.rpm
     openafs-authlibs-devel-1.4.14-82.sl5.i686.rpm
     openafs-client-1.4.14-82.sl5.i686.rpm
     openafs-compat-1.4.14-82.sl5.i686.rpm
     openafs-debug-1.4.14-82.sl5.i686.rpm
     openafs-debuginfo-1.4.14-82.sl5.i686.rpm
     openafs-devel-1.4.14-82.sl5.i686.rpm
     openafs-kernel-source-1.4.14-82.sl5.i686.rpm
     openafs-kpasswd-1.4.14-82.sl5.i686.rpm
     openafs-krb5-1.4.14-82.sl5.i686.rpm
     openafs-server-1.4.14-82.sl5.i686.rpm

SL6
   x86_64
     kmod-openafs-1.6.1-114.sl6.71.x86_64.rpm
     openafs-1.6.1-114.sl6.x86_64.rpm
     openafs-authlibs-1.6.1-114.sl6.x86_64.rpm
     openafs-authlibs-devel-1.6.1-114.sl6.x86_64.rpm
     openafs-client-1.6.1-114.sl6.x86_64.rpm
     openafs-compat-1.6.1-114.sl6.x86_64.rpm
     openafs-devel-1.6.1-114.sl6.x86_64.rpm
     openafs-kernel-source-1.6.1-114.sl6.x86_64.rpm
     openafs-kpasswd-1.6.1-114.sl6.x86_64.rpm
     openafs-krb5-1.6.1-114.sl6.x86_64.rpm
     openafs-plumbing-tools-1.6.1-114.sl6.x86_64.rpm
     openafs-server-1.6.1-114.sl6.x86_64.rpm

   i386
     kmod-openafs-1.6.1-114.sl6.71.i686.rpm
     openafs-1.6.1-114.sl6.i686.rpm
     openafs-authlibs-1.6.1-114.sl6.i686.rpm
     openafs-authlibs-devel-1.6.1-114.sl6.i686.rpm
     openafs-client-1.6.1-114.sl6.i686.rpm
     openafs-compat-1.6.1-114.sl6.i686.rpm
     openafs-devel-1.6.1-114.sl6.i686.rpm
     openafs-kernel-source-1.6.1-114.sl6.i686.rpm
     openafs-kpasswd-1.6.1-114.sl6.i686.rpm
     openafs-krb5-1.6.1-114.sl6.i686.rpm
     openafs-plumbing-tools-1.6.1-114.sl6.i686.rpm
     openafs-server-1.6.1-114.sl6.i686.rpm

ATOM RSS1 RSS2