First published: Thu Nov 22 2018(Updated: )
A flaw was found in pacemaker. Insufficient verification of client-side authentication combined with other IPC weaknesses leads to local privilege escalation.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Clusterlabs Pacemaker | <=2.0.0 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Canonical Ubuntu Linux | =19.04 | |
Fedoraproject Fedora | =28 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =42.3 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Eus | =8.1 | |
Redhat Enterprise Linux Eus | =8.2 | |
Redhat Enterprise Linux Eus | =8.4 | |
Redhat Enterprise Linux Eus | =8.6 | |
Redhat Enterprise Linux Server Aus | =8.2 | |
Redhat Enterprise Linux Server Aus | =8.4 | |
Redhat Enterprise Linux Server Aus | =8.6 | |
Redhat Enterprise Linux Server Tus | =8.2 | |
Redhat Enterprise Linux Server Tus | =8.4 | |
Redhat Enterprise Linux Server Tus | =8.6 | |
redhat/pacemaker | <2.0.2 | 2.0.2 |
debian/pacemaker | 2.0.5-2 2.1.5-1+deb12u1 2.1.8-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16877 is a vulnerability in pacemaker's client-server authentication, allowing a local attacker to achieve local privilege escalation.
CVE-2018-16877 has a severity rating of 7.8 (high).
Versions up to and including 2.0.0 of Clusterlabs Pacemaker, Canonical Ubuntu Linux 16.04, Ubuntu Linux 18.04, Ubuntu Linux 18.10, Ubuntu Linux 19.04, Fedora 28, Fedora 29, Fedora 30, Debian Debian Linux 9.0, openSUSE Leap 15.0, openSUSE Leap 42.3, Redhat Enterprise Linux 8.0, Redhat Enterprise Linux Eus 8.1, Redhat Enterprise Linux Eus 8.2, Redhat Enterprise Linux Eus 8.4, Redhat Enterprise Linux Eus 8.6, Redhat Enterprise Linux Server Aus 8.2, Redhat Enterprise Linux Server Aus 8.4, Redhat Enterprise Linux Server Aus 8.6, Redhat Enterprise Linux Server Tus 8.2, Redhat Enterprise Linux Server Tus 8.4, and Redhat Enterprise Linux Server Tus 8.6 are affected by CVE-2018-16877.
A local attacker can exploit CVE-2018-16877 by combining the pacemaker vulnerability with other inter-process communication weaknesses to escalate their privileges.
To fix CVE-2018-16877, update pacemaker to version 2.0.2 or later for Red Hat systems, or version 1.1.14-2ubuntu1.6 or later for Ubuntu systems.