fence: Multiple symlink vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201009-09 / fence |
| Release Date |
September 29, 2010 |
| Latest Revision |
September 29, 2010: 01 |
| Impact |
normal |
| Exploitable |
local |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| sys-cluster/fence |
<
2.03.09 |
|
All supported architectures
|
Related bugreports:
#240576
Synopsis
fence contains multiple programs containing vulnerabilities that may allow
local users to overwrite arbitrary files via a symlink attack.
2.
Impact Information
Background
fence is an I/O group fencing system.
Description
The fence_apc, fence_apc_snmp (CVE-2008-4579) and fence_manual
(CVE-2008-4580) programs contain symlink vulnerabilities.
Impact
These vulnerabilities may allow arbitrary files to be overwritten with
root privileges.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
Gentoo discontinued support for fence. All fence users should uninstall
and choose another software that provides the same functionality.
Code Listing 3.1: Resolution |
# emerge --unmerge sys-cluster/fence
|
4.
References
|