RHSA-2013:0691High
Red Hat Security Advisory: Red Hat Storage 2.0 security, bug fix, and enhancement update #4
🔗 CVE IDs covered (3)
📋 Description
CVE-2012-4406 — Openstack-Swift: insecure use of python pickle() CVE-2012-5635 — GlusterFS: insecure temporary file creation CVE-2012-5638 — sanlock world writable /var/log/sanlock.log
🎯 Affected products84
- Red Hat Storage 2.0 Console
- Red Hat Storage Native Client for Red Hat Enterprise Linux 5
- Red Hat Storage Native Client for Red Hat Enterprise Linux 6
- Red Hat Storage Server 2.0
- appliance-0:1.7.1-1.el6rhs.src as a component of Red Hat Storage Server 2.0
- appliance-base-0:1.7.1-1.el6rhs.noarch as a component of Red Hat Storage Server 2.0
- augeas-0:0.9.0-1.el6.src as a component of Red Hat Storage Server 2.0
- augeas-0:0.9.0-1.el6.x86_64 as a component of Red Hat Storage Server 2.0
- augeas-debuginfo-0:0.9.0-1.el6.x86_64 as a component of Red Hat Storage Server 2.0
- augeas-devel-0:0.9.0-1.el6.x86_64 as a component of Red Hat Storage Server 2.0
- augeas-libs-0:0.9.0-1.el6.x86_64 as a component of Red Hat Storage Server 2.0
- gluster-swift-0:1.4.8-5.el6rhs.noarch as a component of Red Hat Storage Server 2.0
- gluster-swift-0:1.4.8-5.el6rhs.src as a component of Red Hat Storage Server 2.0
- gluster-swift-account-0:1.4.8-5.el6rhs.noarch as a component of Red Hat Storage Server 2.0
- gluster-swift-container-0:1.4.8-5.el6rhs.noarch as a component of Red Hat Storage Server 2.0
- gluster-swift-doc-0:1.4.8-5.el6rhs.noarch as a component of Red Hat Storage Server 2.0
- gluster-swift-object-0:1.4.8-5.el6rhs.noarch as a component of Red Hat Storage Server 2.0
- gluster-swift-proxy-0:1.4.8-5.el6rhs.noarch as a component of Red Hat Storage Server 2.0
- glusterfs-0:3.3.0.7rhs-1.el5.src as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 5
- glusterfs-0:3.3.0.7rhs-1.el5.x86_64 as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 5
- glusterfs-0:3.3.0.7rhs-1.el6.src as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 6
- glusterfs-0:3.3.0.7rhs-1.el6.x86_64 as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 6
- glusterfs-0:3.3.0.7rhs-1.el6rhs.src as a component of Red Hat Storage Server 2.0
- glusterfs-0:3.3.0.7rhs-1.el6rhs.x86_64 as a component of Red Hat Storage Server 2.0
- glusterfs-debuginfo-0:3.3.0.7rhs-1.el5.x86_64 as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 5
- glusterfs-debuginfo-0:3.3.0.7rhs-1.el6.x86_64 as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 6
- glusterfs-debuginfo-0:3.3.0.7rhs-1.el6rhs.x86_64 as a component of Red Hat Storage Server 2.0
- glusterfs-devel-0:3.3.0.7rhs-1.el5.x86_64 as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 5
- glusterfs-devel-0:3.3.0.7rhs-1.el6.x86_64 as a component of Red Hat Storage Native Client for Red Hat Enterprise Linux 6
- glusterfs-devel-0:3.3.0.7rhs-1.el6rhs.x86_64 as a component of Red Hat Storage Server 2.0
- +54 more not shown
✅ Remediation
All users of Red Hat Storage are advised to upgrade to these updated packages. Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2013:0691
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/knowledge/docs/Red_Hat_Storage/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=854757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=856206
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=859387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=869724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=876679
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=883590
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=886364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=887010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=895841
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=902213
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=922572
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=923674
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_0691.json