Skip to navigation

Security Advisory Important: cobbler security update

Advisory: RHSA-2010:0775-1
Type: Security Advisory
Severity: Important
Issued on: 2010-10-18
Last updated on: 2010-10-18
Affected Products: Red Hat Network Satellite (v. 5.3 for RHEL 4)
Red Hat Network Satellite (v. 5.3 for RHEL 5)
CVEs (cve.mitre.org): CVE-2010-2235

Details

An updated cobbler package that fixes one security issue is now available
for Red Hat Network Satellite Server 5.3.

The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.

Cobbler is a network install server. Cobbler supports PXE, virtualized
installs, and re-installing existing Linux machines. Cheetah is a template
engine used by Cobbler to process kickstart files.

A code injection flaw was found in the way Cobbler processed templates for
kickstart files. A remote, authenticated user, that has the Configuration
Administrator role privilege, could use this flaw to create a
specially-crafted kickstart template file containing embedded Python code
that could, when processed by Cheetah, execute arbitrary code with root
privileges on the Red Hat Network Satellite Server. (CVE-2010-2235)

Red Hat would like to thank Doug Knight of the University of Alaska for
reporting this issue.

Users of Red Hat Network Satellite Server 5.3 are advised to upgrade to
this updated cobbler package, which contains backported patches to correct
this issue. Red Hat Network Satellite Server must be restarted
("/usr/sbin/rhn-satellite restart") for this update to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

Red Hat Network Satellite (v. 5.3 for RHEL 4)

SRPMS:
cobbler-1.6.6-15.el4sat.src.rpm     MD5: 6b6dbaa6c0638a1a450f42dd5d23ea68
SHA-256: 4bf988701f8586420e5d6327fbd09252dad83c483a09a1053936b61f7c795d9f
 
IA-32:
cobbler-1.6.6-15.el4sat.i386.rpm     MD5: 7ee8ec451ca661c21d0555a4aba280f2
SHA-256: 612c9387752c43e5c3be11915dd3b9d4557798525bc594e4135d4c576c03a5e1
 
s390:
cobbler-1.6.6-15.el4sat.s390.rpm     MD5: c9a1a7321cdec16d66ed37cb3155995e
SHA-256: f1c6c8dece2b634fc59c425a36e04a55df166f129fd3d6e853e53da97942ad91
 
s390x:
cobbler-1.6.6-15.el4sat.s390x.rpm     MD5: 715d8ece08fbd20511dd22fbd866844a
SHA-256: c6e66aa5a81bfcf8b90df593365f67b7b7fa664fb6de7383619ff2d0850835fe
 
x86_64:
cobbler-1.6.6-15.el4sat.x86_64.rpm     MD5: a549bc0c5870675ba1d53f0cdf5164ad
SHA-256: f331e989da90e7cac7b11abdcd10cc81a8f6e49790786e5bce5bc93969d6c103
 
Red Hat Network Satellite (v. 5.3 for RHEL 5)

SRPMS:
cobbler-1.6.6-15.el5sat.src.rpm     MD5: e8a381bf5f75f15462dc612375cd5053
SHA-256: 7b1c3e18849ad966cd5c553fea9ce09d38d0b0492e64b79632ec6aa0422b3694
 
IA-32:
cobbler-1.6.6-15.el5sat.i386.rpm     MD5: ec8cb89c97f37613222ba4eee101b5ad
SHA-256: 80a98adfc00b6b784c69159899d642d32bd9350cca8fa35ad50b6498ca1c1f89
 
s390x:
cobbler-1.6.6-15.el5sat.s390x.rpm     MD5: b6f653d24fd9476e0942e8e66d8dd78a
SHA-256: 49041672cf96e4024b1a04e02770676b4c6d835ecce4dd7cbaa0fdd77123f07c
 
x86_64:
cobbler-1.6.6-15.el5sat.x86_64.rpm     MD5: 7620a20ccd03442e9a8a767d069438ce
SHA-256: c3e8f0f90820d2903966e2ac6963aeaee321574e933394b66336cd38522909cc
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

607662 - CVE-2010-2235 RHN Satellite (cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/