Lucene search

K
oraclelinuxOracleLinuxELSA-2018-1060
HistoryApr 30, 2018 - 12:00 a.m.

pcs security update

2018-04-3000:00:00
linux.oracle.com
10

0.006 Low

EPSS

Percentile

78.2%

[0.9.162-5.0.3.el7_5.1]

  • Unlike RHEL we DO have corosync/pacemaker for aarch64 on EL7
  • replace logo pcsd/public/favicon.ico in tarball
  • remove Source1 HAM-logo.png
    [0.9.162-5.el7_5.1]
  • Fixed CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure
  • Fixed CVE-2018-1079 pcs: Privilege escalation via authorized user malicious REST call
  • Fixed CVE-2018-1000119 rack-protection: Timing attack in authenticity_token.rb
  • Resolves: rhbz#1557253