- Issued:
- 2011-12-06
- Updated:
- 2011-12-06
RHBA-2011:1547 - sblim-sfcb bug fix update
Synopsis
sblim-sfcb bug fix update
Type/Severity
Bug Fix Advisory (none)
Topic
An updated sblim-sfcb package that fixes multiple bugs is now available for Red Hat Enterprise Linux 6.
Description
Small Footprint CIM Broker (sblim-sfcb) is a Common Information Model (CIM) server conforming to the CIM Operations over the HTTP protocol. The SFCB CIM server is robust and resource-efficient, and is therefore particularly-suited for embedded and resource-constrained environments. The sblim-sfcb package supports providers written against the Common Manageability Programming Interface (CMPI).
The sblim-sfcb package has been upgraded to upstream version 1.3.11, which provides a number of bug fixes over the previous version. (BZ#633580)
In addition, this update fixes the following four bugs:
-
When using the sfcbrepos command without the "-c" option to specify the location of the CIM schema, an error message occurred. The issue was caused by using the default CIM schema location (the /usr/lib/sfcb/CIM/ directory), which does not exist on Red Hat Enterprise Linux systems. This issue has been fixed and sfcbrepos now reflects the correct CIM schema location (the /usr/share/mof/cim-current/ directory). (BZ#618080)
-
The sfcb system group, which is used by PAM for basic authentication, was not created automatically during package installation. This issue has been fixed and the group is now created correctly. (BZ#618081)
-
The sblim-sfcb package was compiled without the Unix domain socket local connection functionality. This issue has been fixed and this feature is now enabled in the SFCB CIM server. (BZ#620303)
-
Due to missing checks on pointer validity when freeing memory in certain parts of the code, the SBLIM Web-Based Enterprise Management (WBEM) Command Line Interface (sblim-wbemcli) terminated unexpectedly with a segmentation fault upon successful completion of a CIM request. With this update, the missing checks have been added, pointers are now tested for NULL before an attemp to free the memory and set to NULL explicitly after the memory is freed. Segmentation faults no longer occur and sblim-wbemcli no longer crashes in the scenario described. (BZ#745261)
All users of sblim-sfcb are advised to upgrade to this updated package, which fixes these bugs.
Solution
Before applying this update, make sure that all previously-released errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at This content is not included.https://access.redhat.com/kb/docs/DOC-11259
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux for Power, big endian | 6 | ppc64 |
| Red Hat Enterprise Linux for IBM z Systems | 6 | s390x |
| Red Hat Enterprise Linux Workstation | 6 | x86_64 |
| Red Hat Enterprise Linux Workstation | 6 | i386 |
| Red Hat Enterprise Linux Server | 6 | x86_64 |
| Red Hat Enterprise Linux Server | 6 | i386 |
| Red Hat Enterprise Linux Server from RHUI | 6 | x86_64 |
| Red Hat Enterprise Linux Server from RHUI | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) | 6 | s390x |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) | 6 | s390x |
Updated Packages
- sblim-sfcb-1.3.11-2.el6.i686.rpm
- sblim-sfcb-1.3.11-2.el6.s390x.rpm
- sblim-sfcb-1.3.11-2.el6.x86_64.rpm
- sblim-sfcb-1.3.11-2.el6.ppc64.rpm
- sblim-sfcb-debuginfo-1.3.11-2.el6.s390x.rpm
- sblim-sfcb-debuginfo-1.3.11-2.el6.x86_64.rpm
- sblim-sfcb-debuginfo-1.3.11-2.el6.ppc64.rpm
- sblim-sfcb-1.3.11-2.el6.src.rpm
- sblim-sfcb-debuginfo-1.3.11-2.el6.i686.rpm
Fixes
- This content is not included.BZ - 618080
- This content is not included.BZ - 618081
- This content is not included.BZ - 620303
CVEs
(none)
References
(none)
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.