Bug 498985

Summary: rgmanager is affected by several symlink attack vulnerabilities
Product: [Retired] Red Hat Cluster Suite Reporter: Fabio Massimo Di Nitto <fdinitto>
Component: rgmanagerAssignee: Lon Hohberger <lhh>
Status: CLOSED ERRATA QA Contact: Cluster QE <mspqa-list>
Severity: urgent Docs Contact:
Priority: high    
Version: 4CC: bstevens, cfeist, cluster-maint, djansa, fnadge, iannis, swhiteho, tdunnon, thoger
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rgmanager-1.9.88-1.el4 Doc Type: Bug Fix
Doc Text:
Previously, the rgmanager contained several symlink vulnerabilities. With this update, there are no more vulnerabilities in the rgmanager.
Story Points: ---
Clone Of: 469338 Environment:
Last Closed: 2011-02-16 15:09:24 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 3 Florian Nadge 2011-01-03 14:10:24 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
Previously, the isAlive check could fail if two nodes used the same file name. With this update, the isAlive function prevents two nodes from using the same file name.

Comment 4 Florian Nadge 2011-01-03 14:11:11 UTC
    Technical note updated. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    Diffed Contents:
@@ -1 +1 @@
-Previously, the isAlive check could fail if two nodes used the same file name. With this update, the isAlive function prevents two nodes from using the same file name.+Previously, the rgmanager contained several symlink vulnerabilities. With this update, there are no more vulnerabilities in the rgmanager.

Comment 5 Huzaifa S. Sidhpurwala 2011-01-31 05:58:14 UTC
*** Bug 519686 has been marked as a duplicate of this bug. ***

Comment 6 errata-xmlrpc 2011-02-16 15:09:24 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2011-0264.html