- Issued:
- 2017-04-11
- Updated:
- 2017-04-11
RHBA-2017:0896 - Red Hat Satellite server spacewalk-backend bug fix update
Synopsis
Red Hat Satellite server spacewalk-backend bug fix update
Type/Severity
Bug Fix Advisory None
Topic
Updated spacewalk-backend package that delivers a configuration setting to relax white space enforcement in the HTTPD running on Satellite Server.
Description
Red Hat Satellite is a systems management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and remote management of multiple Linux deployments with a single, centralized tool. The spacewalk-backend packages contain the code for the python code that manages the server side of the client-to-satellite-server communication paths.
This update fixes the following issue:
- When the fix for https://bugzilla.redhat.com/show_bug.cgi?id=1412974, CVE-2016-8743 is released and applied, httpd will strictly enforce white space constraints on incoming HTTP requests. A previous release of the yum-rhn-plugin for Satellite clients contains a bug that results in that new httpd service rejecting requests coming from such clients. In order to avoid breaking yum communication between a Satellite instance and its clients, this update puts in place a configuration option that is recognized only by the newer versions of httpd, which relaxes the white space processing to its existing state.
This erratum releases the spacewalk-backend with the configuration change for the following Satellite versions:
-
5.7 (BZ#1422518)
-
5.6 (BZ#1427633)
-
5.5 (BZ#1430528)
-
5.4 (BZ#1430530)
-
In addition, a previously-released update for Satellite-5.5 is included. Prior to this update, an Inter-Satellite Sync operation in some cases did not correctly handle non-ASCII characters (for example Unicode characters in the name of a package maintainer), which could lead to the synchronization failing with a "Unicode Decode Error". This update provides a tool that allows affected customers to fix this problem by running the "update-packages --update-changelog" command on their Satellites. (BZ#1165238)
All users of Red Hat Satellite are advised to upgrade to this updated package, which addresses this issue.
Solution
Before applying this update, make sure all previously-released errata relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Satellite | 5.7 | x86_64 |
| Red Hat Satellite | 5.7 | s390x |
| Red Hat Satellite | 5.6 | x86_64 |
| Red Hat Satellite | 5.6 | x86_64 |
| Red Hat Satellite | 5.6 | s390x |
| Red Hat Satellite with Embedded Oracle | 5.5 | x86_64 |
| Red Hat Satellite with Embedded Oracle | 5.5 | x86_64 |
| Red Hat Satellite with Embedded Oracle | 5.5 | s390x |
| Red Hat Satellite with Embedded Oracle | 5.4 | x86_64 |
| Red Hat Satellite with Embedded Oracle | 5.4 | x86_64 |
| Red Hat Satellite with Embedded Oracle | 5.4 | s390x |
| Red Hat Satellite with Embedded Oracle | 5.4 | i386 |
Updated Packages
- spacewalk-backend-2.0.3-44.el5sat.src.rpm
- spacewalk-backend-xmlrpc-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-sql-postgresql-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-iss-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-iss-export-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-server-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-sql-oracle-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-applet-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-xml-export-libs-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-package-push-server-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-xml-export-libs-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-sql-oracle-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-iss-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-iss-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-iss-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-xp-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-iss-export-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-config-files-tool-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-config-files-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-sql-oracle-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-app-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-libs-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-package-push-server-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-tools-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-package-push-server-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-iss-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-libs-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-sql-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-tools-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-config-files-tool-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-xmlrpc-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-2.3.3-48.el6sat.src.rpm
- spacewalk-backend-config-files-tool-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-tools-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-xmlrpc-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-app-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-tools-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-config-files-tool-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-applet-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-package-push-server-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-server-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-1.7.38-56.el6sat.src.rpm
- spacewalk-backend-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-1.2.13-84.el5sat.src.rpm
- spacewalk-backend-app-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-applet-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-2.0.3-44.el6sat.src.rpm
- spacewalk-backend-package-push-server-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-sql-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-iss-export-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-server-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-xmlrpc-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-tools-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-server-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-xp-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-config-files-common-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-config-files-common-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-applet-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-config-files-tool-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-1.2.13-84.el6sat.src.rpm
- spacewalk-backend-libs-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-applet-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-xml-export-libs-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-xmlrpc-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-sql-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-applet-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-config-files-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-iss-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-server-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-xp-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-server-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-config-files-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-config-files-tool-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-sql-oracle-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-iss-export-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-xmlrpc-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-tools-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-upload-server-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-app-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-sql-oracle-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-config-files-common-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-sql-postgresql-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-config-files-common-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-config-files-common-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-sql-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-sql-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-sql-oracle-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-xp-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-libs-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-xml-export-libs-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-app-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-sql-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-libs-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-config-files-common-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-app-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-config-files-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-libs-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-config-files-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-iss-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-sql-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-xmlrpc-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-xml-export-libs-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-1.7.38-56.el5sat.src.rpm
- spacewalk-backend-iss-export-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-package-push-server-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-sql-oracle-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-config-files-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-tools-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-xml-export-libs-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-iss-export-1.2.13-84.el5sat.noarch.rpm
- spacewalk-backend-config-files-2.0.3-44.el5sat.noarch.rpm
- spacewalk-backend-server-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-upload-server-1.2.13-84.el6sat.noarch.rpm
- spacewalk-backend-config-files-tool-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-2.0.3-44.el6sat.noarch.rpm
- spacewalk-backend-libs-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-app-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-package-push-server-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-sql-postgresql-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-xml-export-libs-2.3.3-48.el6sat.noarch.rpm
- spacewalk-backend-applet-1.7.38-56.el6sat.noarch.rpm
- spacewalk-backend-config-files-common-1.7.38-56.el5sat.noarch.rpm
- spacewalk-backend-iss-export-1.7.38-56.el5sat.noarch.rpm
Fixes
(none)
CVEs
(none)
References
(none)
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.