Red Hat Security Advisory: CloudForms 4.6.6 security, bug fix and enhancement update
🔗 CVE IDs covered (4)
📋 Description
CVE-2018-1053 — postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask CVE-2018-1058 — postgresql: Uncontrolled search path element in pg_dump and other client applications CVE-2018-10915 — postgresql: Certain host connection parameters defeat client-side security defenses CVE-2018-10925 — postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
🎯 Affected products30
- CloudForms Management Engine 5.9
- cfme-0:5.9.6.5-3.el7cf.src as a component of CloudForms Management Engine 5.9
- cfme-0:5.9.6.5-3.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-amazon-smartstate-0:5.9.6.5-2.el7cf.src as a component of CloudForms Management Engine 5.9
- cfme-amazon-smartstate-0:5.9.6.5-2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-appliance-0:5.9.6.5-1.el7cf.src as a component of CloudForms Management Engine 5.9
- cfme-appliance-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-appliance-common-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-appliance-debuginfo-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-appliance-tools-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-debuginfo-0:5.9.6.5-3.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-gemset-0:5.9.6.5-2.el7cf.src as a component of CloudForms Management Engine 5.9
- cfme-gemset-0:5.9.6.5-2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- cfme-gemset-debuginfo-0:5.9.6.5-2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- dbus-api-service-0:1.0.1-3.1.el7cf.src as a component of CloudForms Management Engine 5.9
- dbus-api-service-0:1.0.1-3.1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- httpd-configmap-generator-0:0.2.2-1.2.el7cf.src as a component of CloudForms Management Engine 5.9
- httpd-configmap-generator-0:0.2.2-1.2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-0:9.6.10-1PGDG.el7at.src as a component of CloudForms Management Engine 5.9
- postgresql96-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-contrib-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-debuginfo-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-devel-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-docs-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-libs-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-plperl-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-plpython-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-pltcl-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-server-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
- postgresql96-test-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automatically restarted after installing this update. After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: Upstream suggests the following mitigation can be used to protect against this security flaw: https://wiki.postgresql.org/wiki/A_Guide_to_CVE-2018-1058:_Protect_Your_Search_Path
🔗 References (68)
- selfhttps://access.redhat.com/errata/RHSA-2018:3816
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.6/html/release_notes
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1539619
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1547044
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1609891
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1610547
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1612619
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1618836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1623562
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1634809
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1635034
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1635255
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1635759
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1635788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1638501
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1639351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1639353
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1639364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1640194
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1640258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1640629
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1640631
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1641771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1643042
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1643261
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1643263
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1643539
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1643959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1644410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1645198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1645204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646561
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646564
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646571
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646599
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646605
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646606
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646613
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646629
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1646646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1647056
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1647108
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1647188
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1647489
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1648674
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1648948
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1648955
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1648991
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1649033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1649380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1649419
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1650691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1651291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1651347
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1651391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1653417
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1653710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1654436
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1654463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1655081
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1655143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1655773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1656168
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1656169
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_3816.json