Important: cobbler security update
| Advisory: | RHSA-2010:0775-1 |
|---|---|
| Type: | Security Advisory |
| Severity: | Important |
| Issued on: | 2010-10-18 |
| Last updated on: | 2010-10-18 |
| Affected Products: | Red Hat Network Satellite (v. 5.3 for RHEL 4) Red Hat Network Satellite (v. 5.3 for RHEL 5) |
| CVEs (cve.mitre.org): |
CVE-2010-2235 |
Details
An updated cobbler package that fixes one security issue is now available
for Red Hat Network Satellite Server 5.3.
The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.
Cobbler is a network install server. Cobbler supports PXE, virtualized
installs, and re-installing existing Linux machines. Cheetah is a template
engine used by Cobbler to process kickstart files.
A code injection flaw was found in the way Cobbler processed templates for
kickstart files. A remote, authenticated user, that has the Configuration
Administrator role privilege, could use this flaw to create a
specially-crafted kickstart template file containing embedded Python code
that could, when processed by Cheetah, execute arbitrary code with root
privileges on the Red Hat Network Satellite Server. (CVE-2010-2235)
Red Hat would like to thank Doug Knight of the University of Alaska for
reporting this issue.
Users of Red Hat Network Satellite Server 5.3 are advised to upgrade to
this updated cobbler package, which contains backported patches to correct
this issue. Red Hat Network Satellite Server must be restarted
("/usr/sbin/rhn-satellite restart") for this update to take effect.
Solution
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259
Updated packages
| Red Hat Network Satellite (v. 5.3 for RHEL 4) | |
| SRPMS: | |
| cobbler-1.6.6-15.el4sat.src.rpm | MD5: 6b6dbaa6c0638a1a450f42dd5d23ea68 SHA-256: 4bf988701f8586420e5d6327fbd09252dad83c483a09a1053936b61f7c795d9f |
| IA-32: | |
| cobbler-1.6.6-15.el4sat.i386.rpm | MD5: 7ee8ec451ca661c21d0555a4aba280f2 SHA-256: 612c9387752c43e5c3be11915dd3b9d4557798525bc594e4135d4c576c03a5e1 |
| s390: | |
| cobbler-1.6.6-15.el4sat.s390.rpm | MD5: c9a1a7321cdec16d66ed37cb3155995e SHA-256: f1c6c8dece2b634fc59c425a36e04a55df166f129fd3d6e853e53da97942ad91 |
| s390x: | |
| cobbler-1.6.6-15.el4sat.s390x.rpm | MD5: 715d8ece08fbd20511dd22fbd866844a SHA-256: c6e66aa5a81bfcf8b90df593365f67b7b7fa664fb6de7383619ff2d0850835fe |
| x86_64: | |
| cobbler-1.6.6-15.el4sat.x86_64.rpm | MD5: a549bc0c5870675ba1d53f0cdf5164ad SHA-256: f331e989da90e7cac7b11abdcd10cc81a8f6e49790786e5bce5bc93969d6c103 |
| Red Hat Network Satellite (v. 5.3 for RHEL 5) | |
| SRPMS: | |
| cobbler-1.6.6-15.el5sat.src.rpm | MD5: e8a381bf5f75f15462dc612375cd5053 SHA-256: 7b1c3e18849ad966cd5c553fea9ce09d38d0b0492e64b79632ec6aa0422b3694 |
| IA-32: | |
| cobbler-1.6.6-15.el5sat.i386.rpm | MD5: ec8cb89c97f37613222ba4eee101b5ad SHA-256: 80a98adfc00b6b784c69159899d642d32bd9350cca8fa35ad50b6498ca1c1f89 |
| s390x: | |
| cobbler-1.6.6-15.el5sat.s390x.rpm | MD5: b6f653d24fd9476e0942e8e66d8dd78a SHA-256: 49041672cf96e4024b1a04e02770676b4c6d835ecce4dd7cbaa0fdd77123f07c |
| x86_64: | |
| cobbler-1.6.6-15.el5sat.x86_64.rpm | MD5: 7620a20ccd03442e9a8a767d069438ce SHA-256: c3e8f0f90820d2903966e2ac6963aeaee321574e933394b66336cd38522909cc |
| (The unlinked packages above are only available from the Red Hat Network) | |
Bugs fixed (see bugzilla for more information)
607662 - CVE-2010-2235 RHN Satellite (cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file
References
http://www.redhat.com/security/updates/classification/#important
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/