int(4846)

Vulnerability Bulletins


Acceso no autorizado en Red Hat Cluster Project

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de privilegios
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Red Hat Cluster Project 2.x

Description

Se ha descubierto una vulnerabilidad en Red Hat Cluster Project 2.x.

Un atacante remoto podría obtener acceso no autorizado y modificar ficheros arbitrarios mediante ataques de enlaces simbólicos sobre ficheros en /tmp.

Solution



Actualización de software

Red Hat (RHSA-2009:1337-2)
Red Hat Enterprise Linux (v. 5 servidor)
Red Hat Enterprise Linux Desktop (v. 5 cliente)
https://rhn.redhat.com/

Red Hat (RHSA-2009:1339-2)
RHEL Clustering (v. 5 servidor)
https://rhn.redhat.com/

Red Hat (RHSA-2009:1341-2)
RHEL Desktop Workstation (v. 5 cliente)
Red Hat Enterprise Linux (v. 5 servidor)
https://rhn.redhat.com/

Standar resources

Property Value
CVE CVE-2008-4579
CVE-2008-6552
BID

Other resources

Red Hat Security Advisory (RHSA-2009:1337-2)
https://rhn.redhat.com/errata/RHSA-2009-1337.html

Red Hat Security Advisory (RHSA-2009:1339-2)
https://rhn.redhat.com/errata/RHSA-2009-1339.html

Red Hat Security Advisory (RHSA-2009:1341-2)
https://rhn.redhat.com/errata/RHSA-2009-1341.html

Red Hat Security Advisory (RHSA-2011:0265-1)
https://www.redhat.com/archives/enterprise-watch-list/2011-February/msg00016.html

Version history

Version Comments Date
1.0 Aviso emitido 2009-09-03
1.1 Aviso actualizado por Red Hat (RHSA-2011:0265-1) 2011-02-18