SCIENTIFIC-LINUX-ERRATA Archives

November 2014

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 3 Nov 2014 17:54:30 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (23 lines)
Synopsis:          Moderate: luci security, bug fix, and enhancement update
Advisory ID:       SLSA-2014:1390-2
Issue Date:        2014-10-14
CVE Numbers:       CVE-2014-3593
--

It was discovered that luci used eval() on inputs containing strings from
the cluster configuration file when generating its web pages. An attacker
with privileges to create or edit the cluster configuration could use this
flaw to execute arbitrary code as the luci user on a host running luci.
(CVE-2014-3593)
--

SL6
  x86_64
    luci-0.26.0-63.el6.x86_64.rpm
    luci-debuginfo-0.26.0-63.el6.x86_64.rpm
  i386
    luci-0.26.0-63.el6.i686.rpm
    luci-debuginfo-0.26.0-63.el6.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2