Red Hat Security Advisory: rhvm-appliance security and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2017-12196 — undertow: Client can use bogus uri in Digest authentication CVE-2018-1073 — ovirt-engine: account enumeration through login to web console CVE-2018-1111 — dhcp: Command injection vulnerability in the DHCP client NetworkManager integration script CVE-2018-5968 — jackson-databind: unsafe deserialization due to incomplete blacklist (incomplete fix for CVE-2017-7525 and CVE-2017-17485) CVE-2018-7750 — python-paramiko: Authentication bypass in transport.py CVE-2018-8088 — slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution
🎯 Affected products6
- Red Hat Virtualization 4 Hypervisor for RHEL 7
- Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.2-20180504.0.el7.noarch as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
- rhvm-appliance-2:4.2-20180504.0.el7.noarch as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.2-20180504.0.el7.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
- rhvm-appliance-2:4.2-20180504.0.el7.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 Workaround: Please access https://access.redhat.com/security/vulnerabilities/3442151 for information on how to mitigate this issue.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2018:1525
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1422982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1463853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1464486
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1467946
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1476755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1503055
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1538332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1548909
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1553525
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1557130
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1561888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1563737
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_1525.json