Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: Pat Riehecky <riehecky-13hema8v3vg <at> public.gmane.org>
Subject: Security ERRATA Low: conga on SL5.x i386/x86_64
Newsgroups: gmane.linux.scientific.errata
Date: Wednesday 16th January 2013 22:10:18 UTC (over 3 years ago)
Synopsis:          Low: conga security, bug fix, and enhancement update
Issue Date:        2013-01-08
CVE Numbers:       CVE-2012-3359
--

It was discovered that luci stored usernames and passwords in session 
cookies.
This issue prevented the session inactivity timeout feature from working
correctly, and allowed attackers able to get access to a session cookie to
obtain the victim's authentication credentials. (CVE-2012-3359)

This update also fixes the following bugs:

* Prior to this update, luci did not allow the fence_apc_snmp agent to be
configured. As a consequence, users could not configure or view an existing
configuration for fence_apc_snmp. This update adds a new screen that allows
fence_apc_snmp to be configured.

* Prior to this update, luci did not allow the SSL operation of the 
fence_ilo
fence agent to be enabled or disabled. As a consequence, users could not
configure or view an existing configuration for the 'ssl' attribute for
fence_ilo. This update adds a checkbox to show whether the SSL operation is
enabled and allows users to edit that attribute.

* Prior to this update, luci did not allow the "identity_file" attribute 
of the
fence_ilo_mp fence agent to be viewed or edited. As a consequence, users 
could
not configure or view an existing configuration for the "identity_file"
attribute of the fence_ilo_mp fence agent. This update adds a text input 
box to
show the current state of the "identity_file" attribute of fence_ilo_mp and
allows users to edit that attribute.

* Prior to this update, redundant files and directories remained on the
file
system at /var/lib/luci/var/pts and /usr/lib{,64}/luci/zope/var/pts when
the
luci package was uninstalled. This update removes these files and 
directories
when the luci package is uninstalled.

* Prior to this update, the "restart-disable" recovery policy was not 
displayed
in the recovery policy list from which users could select when they 
configure a
recovery policy for a failover domain. As a consequence, the 
"restart-disable"
recovery policy could not be set with the luci GUI. This update adds the
"restart-disable" recovery option to the recovery policy pulldown list.

* Prior to this update, line breaks that were not anticipated in the 
"yum list"
output could cause package upgrade and/or installation to fail when
creating
clusters or adding nodes to existing clusters. As a consequence, creating
clusters and adding cluster nodes to existing clusters could fail. This 
update
modifies the ricci daemon to be able to correctly handle line breaks in the
"yum list" output.

In addition, this update adds the following enhancements:

* This update adds support for configuring the Intel iPDU fence agent to
the
luci package.

* This update adds support for viewing and changing the state of the new
'nfsrestart' attribute to the FS and Cluster FS resource agent
configuration
screens.

After installing this update, the luci and ricci services will be restarted
automatically.
--

SL5
   x86_64
     conga-debuginfo-0.12.2-64.el5.x86_64.rpm
     luci-0.12.2-64.el5.x86_64.rpm
     ricci-0.12.2-64.el5.x86_64.rpm
   i386
     conga-debuginfo-0.12.2-64.el5.i386.rpm
     luci-0.12.2-64.el5.i386.rpm
     ricci-0.12.2-64.el5.i386.rpm

- Scientific Linux Development Team
 
CD: 3ms