Description: | Description: The remote host is missing updates announced in advisory RHSA-2011:0264.
The rgmanager package contains the Red Hat Resource Group Manager, which provides high availability for critical server applications.
Multiple insecure temporary file use flaws were discovered in rgmanager and various resource scripts run by rgmanager. A local attacker could use these flaws to overwrite an arbitrary file writable by the rgmanager process (i.e. user root) with the output of rgmanager or a resource agent via a symbolic link attack. (CVE-2008-6552)
It was discovered that certain resource agent scripts set the LD_LIBRARY_PATH environment variable to an insecure value containing empty path elements. A local user able to trick a user running those scripts to run them while working from an attacker-writable directory could use this flaw to escalate their privileges via a specially-crafted dynamic library. (CVE-2010-3389)
Red Hat would like to thank Raphael Geissert for reporting the CVE-2010-3389 issue.
All users of rgmanager are advised to upgrade to this updated package, which corrects these issues.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2011-0264.html
Risk factor : High
CVSS Score: 6.9
|