Ubuntu security notices
USN-3462-1: Pacemaker vulnerabilities
USN-3462-1: Pacemaker vulnerabilities Ubuntu Security Notice USN-3462-1 24th October, 2017 pacemaker vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Pacemaker. Software description pacemaker – Cluster resource manager Details Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handledthe IPC interface. A local attacker could possibly use this issue toexecute arbitrary code with root privileges. (CVE-2016-7035) Alain Moulle discovered that Pacemaker incorrectly handled authentication.A remote attacker could possibly use this issue to shut down connections,leading to a denial of service. This issue only affected Ubuntu 16.04 LTS.(CVE-2016-7797) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: pacemaker 1.1.14-2ubuntu1.2 Ubuntu 14.04 LTS: pacemaker 1.1.10+git20130802-1ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, [ more… ]