|
|
Log in / Subscribe / Register

Scientific Linux alert SLSA-2016:2596-2 (pcs)

From:  Scott Reid <svreid@fnal.gov>
To:  <scientific-linux-errata@listserv.fnal.gov>
Subject:  Security ERRATA Moderate: pcs on SL7.x x86_64
Date:  Wed, 14 Dec 2016 17:52:19 +0000
Message-ID:  <20161214175219.3169.49291@slpackages.fnal.gov>

Synopsis: Moderate: pcs security, bug fix, and enhancement update Advisory ID: SLSA-2016:2596-2 Issue Date: 2016-11-03 CVE Numbers: CVE-2016-0720 CVE-2016-0721 -- The following packages have been upgraded to a newer upstream version: pcs (0.9.152). Security Fix(es): * A Cross-Site Request Forgery (CSRF) flaw was found in the pcsd web UI. A remote attacker could provide a specially crafted web page that, when visited by a user with a valid pcsd session, would allow the attacker to trigger requests on behalf of the user, for example removing resources or restarting/removing nodes. (CVE-2016-0720) * It was found that pcsd did not invalidate cookies on the server side when a user logged out. This could potentially allow an attacker to perform session fixation attacks on pcsd. (CVE-2016-0721) These issues were discovered by Martin Prpic (Red Hat Product Security). Additional Changes: -- SL7 x86_64 pcs-0.9.152-10.el7.x86_64.rpm pcs-debuginfo-0.9.152-10.el7.x86_64.rpm - Scientific Linux Development Team


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds