Gentoo Logo

fence: Multiple symlink vulnerabilities

Content:

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 201009-09 / fence
Release Date September 29, 2010
Latest Revision September 29, 2010: 01
Impact normal
Exploitable local
Package Vulnerable versions Unaffected versions Architecture(s)
sys-cluster/fence < 2.03.09 All supported architectures

Related bugreports: #240576

Synopsis

fence contains multiple programs containing vulnerabilities that may allow local users to overwrite arbitrary files via a symlink attack.

2.  Impact Information

Background

fence is an I/O group fencing system.

Description

The fence_apc, fence_apc_snmp (CVE-2008-4579) and fence_manual (CVE-2008-4580) programs contain symlink vulnerabilities.

Impact

These vulnerabilities may allow arbitrary files to be overwritten with root privileges.

3.  Resolution Information

Workaround

There is no known workaround at this time.

Resolution

Gentoo discontinued support for fence. All fence users should uninstall and choose another software that provides the same functionality.

Code Listing 3.1: Resolution

# emerge --unmerge sys-cluster/fence

4.  References



Print

Page updated September 29, 2010

Summary: This is a Gentoo Linux Security Advisory

Security Team
Contact Address

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.