- Issued:
- 2017-04-11
- Updated:
- 2017-04-11
RHBA-2017:0897 - Bug Fix Advisory
Synopsis
Red Hat Satellite Proxy server spacewalk-backend bug fix update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated spacewalk-backend package that delivers a configuration setting to relax whitespace enforcement in the HTTPD running on the Proxy server.
Description
Red Hat Satellite Proxy is a systems management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and remote management of multiple Linux deployments with a single, centralized tool. The spacewalk-backend packages contain the code for the python code that manages the server side of the client-to-satellite-server communication paths.
This update fixes the following issue:
- When the fix for https://bugzilla.redhat.com/show_bug.cgi?id=1412974, CVE-2016-8743, is released and applied, httpd will strictly enforce whitespace constraints on incoming HTTP requests. A previous release of the yum-rhn-plugin for Satellite clients contains a bug that results in that new httpd service rejecting requests coming from such clients. In order to avoid breaking yum-communication between a Proxy instance and its clients, this update puts in place a configuration option that is recognized only by the newer versions of httpd, which relaxes the whitespace-processing to its existing state.
The erratum releases the spacewalk-backend with the configuration change for the following Proxy versions:
- 5.7 (BZ#1430870)
- 5.6 (BZ#1430875)
- 5.5 (BZ#1430877)
- 5.4 (BZ#1430878)
All users of Red Hat Satellite Proxy are advised to upgrade to this updated package, which addresses this issue.
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Satellite Proxy 5.7 x86_64
- Red Hat Satellite Proxy 5.7 s390x
- Red Hat Satellite Proxy 5.6 for RHEL 6 x86_64
- Red Hat Satellite Proxy 5.6 for RHEL 6 s390x
- Red Hat Satellite Proxy 5.6 for RHEL 5 x86_64
- Red Hat Satellite Proxy 5.6 for RHEL 5 s390x
- Red Hat Satellite Proxy 5.5 for RHEL 6 x86_64
- Red Hat Satellite Proxy 5.5 for RHEL 6 s390x
- Red Hat Satellite Proxy 5.5 for RHEL 5 x86_64
- Red Hat Satellite Proxy 5.5 for RHEL 5 s390x
- Red Hat Satellite Proxy 5.4 for RHEL 6 x86_64
- Red Hat Satellite Proxy 5.4 for RHEL 6 s390x
- Red Hat Satellite Proxy 5.4 for RHEL 5 x86_64
- Red Hat Satellite Proxy 5.4 for RHEL 5 s390x
- Red Hat Satellite Proxy 5.4 for RHEL 5 i386
Fixes
(none)CVEs
(none)
References
(none)
Red Hat Satellite Proxy 5.7
SRPM | |
---|---|
pyliblzma-0.5.3-14.el6sat.src.rpm | SHA-256: 380d35b6120ca81049f2ee0b6708cdd75877a14a203ec6fce53fe9ebc49ac9a0 |
spacewalk-backend-2.3.3-48.el6sat.src.rpm | SHA-256: 558d465c2b92832a26b55343c5c39e8a2ccae5075873a34084625614f5c36bce |
x86_64 | |
pyliblzma-0.5.3-14.el6sat.x86_64.rpm | SHA-256: 48c8a7f8a523c5bffbf651cb50d780ad013a71e7ecc32aa56729367e3445619c |
spacewalk-backend-2.3.3-48.el6sat.noarch.rpm | SHA-256: 383a68eb7280219b0ae2c30b0fb3ad36adfdd96b9332c04f8dc03b71a7ad8a98 |
spacewalk-backend-libs-2.3.3-48.el6sat.noarch.rpm | SHA-256: 0b74ff2eca2886b3f27fdf516670adf2deeaa4631813b636761838765f79c10c |
s390x | |
pyliblzma-0.5.3-14.el6sat.s390x.rpm | SHA-256: 4d253d821bf7ce439a3529441de431aaf6eda73854245b8c3d66b71c8eacae0a |
spacewalk-backend-2.3.3-48.el6sat.noarch.rpm | SHA-256: 383a68eb7280219b0ae2c30b0fb3ad36adfdd96b9332c04f8dc03b71a7ad8a98 |
spacewalk-backend-libs-2.3.3-48.el6sat.noarch.rpm | SHA-256: 0b74ff2eca2886b3f27fdf516670adf2deeaa4631813b636761838765f79c10c |
Red Hat Satellite Proxy 5.6 for RHEL 6
SRPM | |
---|---|
pyliblzma-0.5.3-14.el6sat.src.rpm | SHA-256: 380d35b6120ca81049f2ee0b6708cdd75877a14a203ec6fce53fe9ebc49ac9a0 |
spacewalk-backend-2.0.3-44.el6sat.src.rpm | SHA-256: e6101e944ef6383bc2dbf6e92d3c291c47e353a9bf128f0b547690ab0ac1ddac |
x86_64 | |
pyliblzma-0.5.3-14.el6sat.x86_64.rpm | SHA-256: 48c8a7f8a523c5bffbf651cb50d780ad013a71e7ecc32aa56729367e3445619c |
spacewalk-backend-2.0.3-44.el6sat.noarch.rpm | SHA-256: 92e7d933b5b9ed4928a4227bbaedee998241e4630d087c781decc067ac084bd1 |
spacewalk-backend-libs-2.0.3-44.el6sat.noarch.rpm | SHA-256: 132ef4186251787ba4db2522eb2654589ddfde09377af461f41aef797bc7584a |
s390x | |
pyliblzma-0.5.3-14.el6sat.s390x.rpm | SHA-256: 4d253d821bf7ce439a3529441de431aaf6eda73854245b8c3d66b71c8eacae0a |
spacewalk-backend-2.0.3-44.el6sat.noarch.rpm | SHA-256: 92e7d933b5b9ed4928a4227bbaedee998241e4630d087c781decc067ac084bd1 |
spacewalk-backend-libs-2.0.3-44.el6sat.noarch.rpm | SHA-256: 132ef4186251787ba4db2522eb2654589ddfde09377af461f41aef797bc7584a |
Red Hat Satellite Proxy 5.6 for RHEL 5
SRPM | |
---|---|
spacewalk-backend-2.0.3-44.el5sat.src.rpm | SHA-256: b240201aae89b5523aed03132b5adb58d21c7f95172b9a05b00e67942bc57139 |
x86_64 | |
spacewalk-backend-2.0.3-44.el5sat.noarch.rpm | SHA-256: 79d785b96a8cb46912e775215df66663f8ae38ef2917c267f8af7ce3d9bb6052 |
spacewalk-backend-libs-2.0.3-44.el5sat.noarch.rpm | SHA-256: 7834eb6e3e5c1d768c2b5c50daab57d9d4077c0a0a8bdf5748ba8f2e301d7774 |
s390x | |
spacewalk-backend-2.0.3-44.el5sat.noarch.rpm | SHA-256: 79d785b96a8cb46912e775215df66663f8ae38ef2917c267f8af7ce3d9bb6052 |
spacewalk-backend-libs-2.0.3-44.el5sat.noarch.rpm | SHA-256: 7834eb6e3e5c1d768c2b5c50daab57d9d4077c0a0a8bdf5748ba8f2e301d7774 |
Red Hat Satellite Proxy 5.5 for RHEL 6
SRPM | |
---|---|
spacewalk-backend-1.7.38-56.el6sat.src.rpm | SHA-256: 8f5eece4c5f7926c7f785ebcdda5b3e776c9213e20a4d04a487e7563d0ab08f9 |
x86_64 | |
spacewalk-backend-1.7.38-56.el6sat.noarch.rpm | SHA-256: 3a2f29c0229b54eab8a61cae75f51b2d77215a12f6a148e5d39e8101d40875ea |
spacewalk-backend-libs-1.7.38-56.el6sat.noarch.rpm | SHA-256: 676f2f51096350d884660847cfe95c3ac6ffebc1123a80a3ac7d342fcbb7fb0f |
s390x | |
spacewalk-backend-1.7.38-56.el6sat.noarch.rpm | SHA-256: 3a2f29c0229b54eab8a61cae75f51b2d77215a12f6a148e5d39e8101d40875ea |
spacewalk-backend-libs-1.7.38-56.el6sat.noarch.rpm | SHA-256: 676f2f51096350d884660847cfe95c3ac6ffebc1123a80a3ac7d342fcbb7fb0f |
Red Hat Satellite Proxy 5.5 for RHEL 5
SRPM | |
---|---|
spacewalk-backend-1.7.38-56.el5sat.src.rpm | SHA-256: 9cff859bd7e2799fb189c106b06fdbb1c1d97ad7b6bec02cf914481e8ecbd51b |
x86_64 | |
spacewalk-backend-1.7.38-56.el5sat.noarch.rpm | SHA-256: c8c2885b7914caf7b2d4e732b049e97569a313cbb95f4179ae91cbab4c25622d |
spacewalk-backend-libs-1.7.38-56.el5sat.noarch.rpm | SHA-256: 27305c97ace7a20faa2133c54742057dc046aec0c3dea89bb441cb7076b2cb90 |
s390x | |
spacewalk-backend-1.7.38-56.el5sat.noarch.rpm | SHA-256: c8c2885b7914caf7b2d4e732b049e97569a313cbb95f4179ae91cbab4c25622d |
spacewalk-backend-libs-1.7.38-56.el5sat.noarch.rpm | SHA-256: 27305c97ace7a20faa2133c54742057dc046aec0c3dea89bb441cb7076b2cb90 |
Red Hat Satellite Proxy 5.4 for RHEL 6
SRPM | |
---|---|
spacewalk-backend-1.2.13-84.el6sat.src.rpm | SHA-256: ea54b358dbef169af413b0b3bcaf06179495a846892b0241377e3ffa3045d758 |
x86_64 | |
spacewalk-backend-1.2.13-84.el6sat.noarch.rpm | SHA-256: 515f5cbe4fd0c5221cdf235ded9c2532f5afce3ecf19de107616646a75460d61 |
spacewalk-backend-libs-1.2.13-84.el6sat.noarch.rpm | SHA-256: a1dbcfc89650cc7fa48009e47fc63b8554e8143ad5bcd03d05388d09c86c5a35 |
s390x | |
spacewalk-backend-1.2.13-84.el6sat.noarch.rpm | SHA-256: 515f5cbe4fd0c5221cdf235ded9c2532f5afce3ecf19de107616646a75460d61 |
spacewalk-backend-libs-1.2.13-84.el6sat.noarch.rpm | SHA-256: a1dbcfc89650cc7fa48009e47fc63b8554e8143ad5bcd03d05388d09c86c5a35 |
Red Hat Satellite Proxy 5.4 for RHEL 5
SRPM | |
---|---|
spacewalk-backend-1.2.13-84.el5sat.src.rpm | SHA-256: 32c6597d33581295c62c803ed63cc239799d2577c73aaebd16e21ae92e92b555 |
x86_64 | |
spacewalk-backend-1.2.13-84.el5sat.noarch.rpm | SHA-256: e1405deb2acebed17044b25d4a34637875dfcafcfb916f05bccc11a890c6952f |
spacewalk-backend-libs-1.2.13-84.el5sat.noarch.rpm | SHA-256: 4bd6d76f35644571ac45428dc8faee8aad5283740e1f26d2837844881a14505b |
s390x | |
spacewalk-backend-1.2.13-84.el5sat.noarch.rpm | SHA-256: e1405deb2acebed17044b25d4a34637875dfcafcfb916f05bccc11a890c6952f |
spacewalk-backend-libs-1.2.13-84.el5sat.noarch.rpm | SHA-256: 4bd6d76f35644571ac45428dc8faee8aad5283740e1f26d2837844881a14505b |
i386 | |
spacewalk-backend-1.2.13-84.el5sat.noarch.rpm | SHA-256: e1405deb2acebed17044b25d4a34637875dfcafcfb916f05bccc11a890c6952f |
spacewalk-backend-libs-1.2.13-84.el5sat.noarch.rpm | SHA-256: 4bd6d76f35644571ac45428dc8faee8aad5283740e1f26d2837844881a14505b |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.