- Issued:
- 2012-12-04
- Updated:
- 2012-12-04
RHSA-2012:1543 - Important: CloudForms System Engine 1.1 update
Synopsis
Important: CloudForms System Engine 1.1 update
Type/Severity
Security Advisory Important
Topic
Updated CloudForms System Engine packages that fix multiple security issues, several bugs, and add enhancements are now available.
The Red Hat Security Response Team has rated this update as having important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section.
Description
Red Hat CloudForms is an on-premise hybrid cloud Infrastructure-as-a-Service (IaaS) product that lets you create and manage private and public clouds.
This update fixes bugs in and adds enhancements to the System Engine packages, and upgrades the system to CloudForms 1.1.
This update also fixes the following security issues:
It was discovered that Katello did not properly check user permissions when handling certain requests. An authenticated remote attacker could use this flaw to download consumer certificates or change settings of other users' systems if they knew the target system's UUID. (CVE-2012-5603)
It was discovered that Pulp logged administrative passwords to a world readable log file. A local attacker could use this flaw to control systems deployed and managed by CloudForms. (CVE-2012-3538)
It was discovered that the Pulp configuration file pulp.conf was installed as world readable. A local attacker could use this flaw to view the administrative password, allowing them to control systems deployed and managed by CloudForms. (CVE-2012-4574)
It was discovered that grinder used insecure permissions for its cache directory. A local attacker could use this flaw to access or modify files in the cache. (CVE-2012-5605)
The CVE-2012-5603 issue was discovered by Lukas Zapletal of Red Hat; CVE-2012-3538 was discovered by James Laska of Red Hat; CVE-2012-4574 was discovered by Kurt Seifried of Red Hat; and CVE-2012-5605 was discovered by James Labocki of Red Hat.
After upgrading to these new packages, follow the instructions in the "4.1. Upgrading CloudForms System Engine" section of the CloudForms 1.1 Installation Guide:
To view the full list of changes in this update, view the CloudForms Technical Notes:
Users are advised to upgrade to these updated CloudForms System Engine packages, which resolve these issues and add these enhancements.
Solution
Before applying this update, make sure all previously-released errata relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux Server | 5 | x86_64 |
| Red Hat Enterprise Linux Server | 5 | i386 |
Updated Packages
- gofer-0.66.1-2.el5.src.rpm
- gofer-0.66.1-2.el5.noarch.rpm
- katello-agent-1.1.2-1.el5.noarch.rpm
- gofer-watchdog-0.66.1-2.el5.noarch.rpm
- python-gofer-0.66.1-2.el5.noarch.rpm
- gofer-package-0.66.1-2.el5.noarch.rpm
- katello-agent-1.1.2-1.el5.src.rpm
Fixes
- This content is not included.BZ - 746765
- This content is not included.BZ - 753128
- This content is not included.BZ - 760180
- This content is not included.BZ - 766694
- This content is not included.BZ - 769559
- This content is not included.BZ - 782954
- This content is not included.BZ - 786176
- This content is not included.BZ - 786226
- This content is not included.BZ - 787184
- This content is not included.BZ - 787305
- This content is not included.BZ - 789139
- This content is not included.BZ - 789535
- This content is not included.BZ - 790138
- This content is not included.BZ - 790342
- This content is not included.BZ - 796047
- This content is not included.BZ - 796972
- This content is not included.BZ - 797299
- This content is not included.BZ - 797321
- This content is not included.BZ - 797412
- This content is not included.BZ - 799538
- This content is not included.BZ - 800529
- This content is not included.BZ - 801454
- This content is not included.BZ - 801580
- This content is not included.BZ - 802925
- This content is not included.BZ - 803548
- This content is not included.BZ - 803702
- This content is not included.BZ - 803728
- This content is not included.BZ - 803761
- This content is not included.BZ - 804127
- This content is not included.BZ - 804555
- This content is not included.BZ - 804610
- This content is not included.BZ - 804685
- This content is not included.BZ - 805027
- This content is not included.BZ - 805412
- This content is not included.BZ - 805627
- This content is not included.BZ - 805709
- This content is not included.BZ - 805956
- This content is not included.BZ - 806076
- This content is not included.BZ - 806078
- This content is not included.BZ - 806083
- This content is not included.BZ - 806353
- This content is not included.BZ - 806879
- This content is not included.BZ - 806940
- This content is not included.BZ - 806969
- This content is not included.BZ - 807288
- This content is not included.BZ - 807291
- This content is not included.BZ - 807468
- This content is not included.BZ - 807804
- This content is not included.BZ - 808172
- This content is not included.BZ - 808437
- This content is not included.BZ - 809259
- This content is not included.BZ - 810378
- This content is not included.BZ - 810945
- This content is not included.BZ - 811556
- This content is not included.BZ - 811564
- This content is not included.BZ - 812417
- This content is not included.BZ - 813675
- This content is not included.BZ - 815308
- This content is not included.BZ - 815802
- This content is not included.BZ - 816935
- This content is not included.BZ - 817123
- This content is not included.BZ - 818204
- This content is not included.BZ - 818261
- This content is not included.BZ - 818370
- This content is not included.BZ - 819593
- This content is not included.BZ - 819941
- This content is not included.BZ - 820373
- This content is not included.BZ - 820385
- This content is not included.BZ - 820624
- This content is not included.BZ - 820626
- This content is not included.BZ - 820630
- This content is not included.BZ - 821345
- This content is not included.BZ - 821644
- This content is not included.BZ - 821929
- This content is not included.BZ - 822119
- This content is not included.BZ - 822484
- This content is not included.BZ - 823688
- This content is not included.BZ - 824069
- This content is not included.BZ - 824581
- This content is not included.BZ - 826581
- This content is not included.BZ - 827087
- This content is not included.BZ - 827108
- This content is not included.BZ - 828447
- This content is not included.BZ - 828533
- This content is not included.BZ - 829208
- This content is not included.BZ - 829437
- This content is not included.BZ - 829794
- This content is not included.BZ - 830176
- This content is not included.BZ - 831664
- This content is not included.BZ - 834006
- This content is not included.BZ - 834013
- This content is not included.BZ - 834242
- This content is not included.BZ - 834646
- This content is not included.BZ - 834697
- This content is not included.BZ - 835586
- This content is not included.BZ - 835591
- This content is not included.BZ - 835875
- This content is not included.BZ - 836339
- This content is not included.BZ - 836575
- This content is not included.BZ - 837000
- This content is not included.BZ - 839005
- This content is not included.BZ - 840616
- This content is not included.BZ - 840624
- This content is not included.BZ - 840625
- This content is not included.BZ - 841000
- This content is not included.BZ - 841289
- This content is not included.BZ - 841300
- This content is not included.BZ - 841310
- This content is not included.BZ - 841686
- This content is not included.BZ - 841691
- This content is not included.BZ - 841984
- This content is not included.BZ - 841998
- This content is not included.BZ - 842003
- This content is not included.BZ - 842005
- This content is not included.BZ - 842010
- This content is not included.BZ - 842252
- This content is not included.BZ - 842256
- This content is not included.BZ - 842271
- This content is not included.BZ - 842569
- This content is not included.BZ - 842838
- This content is not included.BZ - 842858
- This content is not included.BZ - 843059
- This content is not included.BZ - 843061
- This content is not included.BZ - 843064
- This content is not included.BZ - 843161
- This content is not included.BZ - 843165
- This content is not included.BZ - 843462
- This content is not included.BZ - 843529
- This content is not included.BZ - 843845
- This content is not included.BZ - 844414
- This content is not included.BZ - 844417
- This content is not included.BZ - 844678
- This content is not included.BZ - 844796
- This content is not included.BZ - 844806
- This content is not included.BZ - 845060
- This content is not included.BZ - 845096
- This content is not included.BZ - 845198
- This content is not included.BZ - 845224
- This content is not included.BZ - 845576
- This content is not included.BZ - 845580
- This content is not included.BZ - 845613
- This content is not included.BZ - 845668
- This content is not included.BZ - 845995
- This content is not included.BZ - 846251
- This content is not included.BZ - 846482
- This content is not included.BZ - 846719
- This content is not included.BZ - 847002
- This content is not included.BZ - 847115
- This content is not included.BZ - 847858
- This content is not included.BZ - 848038
- This content is not included.BZ - 849224
- This content is not included.BZ - 850342
- This content is not included.BZ - 850790
- This content is not included.BZ - 851080
- This content is not included.BZ - 851142
- This content is not included.BZ - 851512
- This content is not included.BZ - 852006
- This content is not included.BZ - 852119
- This content is not included.BZ - 852167
- This content is not included.BZ - 852199
- This content is not included.BZ - 852316
- This content is not included.BZ - 852388
- This content is not included.BZ - 852791
- This content is not included.BZ - 852804
- This content is not included.BZ - 853056
- This content is not included.BZ - 853229
- This content is not included.BZ - 853356
- This content is not included.BZ - 853445
- This content is not included.BZ - 853995
- This content is not included.BZ - 854697
- This content is not included.BZ - 855184
- This content is not included.BZ - 855267
- This content is not included.BZ - 855406
- This content is not included.BZ - 856220
- This content is not included.BZ - 857078
- This content is not included.BZ - 857230
- This content is not included.BZ - 857274
- This content is not included.BZ - 857499
- This content is not included.BZ - 857539
- This content is not included.BZ - 857550
- This content is not included.BZ - 857574
- This content is not included.BZ - 857720
- This content is not included.BZ - 857727
- This content is not included.BZ - 857842
- This content is not included.BZ - 858011
- This content is not included.BZ - 858013
- This content is not included.BZ - 858038
- This content is not included.BZ - 858193
- This content is not included.BZ - 858277
- This content is not included.BZ - 858358
- This content is not included.BZ - 858360
- This content is not included.BZ - 858363
- This content is not included.BZ - 858661
- This content is not included.BZ - 858678
- This content is not included.BZ - 858682
- This content is not included.BZ - 858706
- This content is not included.BZ - 858960
- This content is not included.BZ - 859329
- This content is not included.BZ - 859407
- This content is not included.BZ - 859415
- This content is not included.BZ - 859442
- This content is not included.BZ - 859604
- This content is not included.BZ - 859784
- This content is not included.BZ - 859963
- This content is not included.BZ - 860251
- This content is not included.BZ - 860421
- This content is not included.BZ - 860702
- This content is not included.BZ - 860709
- This content is not included.BZ - 862441
- This content is not included.BZ - 862997
- This content is not included.BZ - 863187
- This content is not included.BZ - 863252
- This content is not included.BZ - 864216
- This content is not included.BZ - 864372
- This content is not included.BZ - 864936
- This content is not included.BZ - 864999
- This content is not included.BZ - 865528
- This content is not included.BZ - 865811
- This content is not included.BZ - 869575
- This content is not included.BZ - 871086
- This content is not included.BZ - 872096
- This content is not included.BZ - 872305
- This content is not included.BZ - 872487
- This content is not included.BZ - 873850
- This content is not included.BZ - 874160
- This content is not included.BZ - 874185
- This content is not included.BZ - 874768
- This content is not included.BZ - 882129
- This content is not included.BZ - 882138
CVEs
References
- https://access.redhat.com/security/updates/classification/#important
- This content is not included.This content is not included.https://access.redhat.com/knowledge/docs/en-US/CloudForms/1.1/html/Installation_Guide/index.html
- This content is not included.This content is not included.https://access.redhat.com/knowledge/docs/en-US/CloudForms/1.1/html/Technical_Notes/index.html
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.