First published: Wed Sep 02 2009(Updated: )
The Cluster Manager (cman) utility provides services for managing a Linux<br>cluster.<br>Multiple insecure temporary file use flaws were found in fence_apc_snmp and<br>ccs_tool. A local attacker could use these flaws to overwrite an arbitrary<br>file writable by a victim running those utilities (typically root) with<br>the output of the utilities via a symbolic link attack. (CVE-2008-4579,<br>CVE-2008-6552)<br>Bug fixes:<br><li> a buffer could overflow if cluster.conf had more than 52 entries per</li> block inside the <cman> block. The limit is now 1024.<br><li> the output of the group_tool dump subcommands were NULL padded.</li> <li> using device="" instead of label="" no longer causes qdiskd to</li> incorrectly exit.<br><li> the IPMI fencing agent has been modified to time out after 10 seconds. It</li> is also now possible to specify a different timeout value with the '-t'<br>option.<br><li> the IPMI fencing agent now allows punctuation in passwords.</li> <li> quickly starting and stopping the cman service no longer causes the</li> cluster membership to become inconsistent across the cluster.<br><li> an issue with lock syncing caused 'receive_own from' errors to be logged</li> to '/var/log/messages'.<br><li> an issue which caused gfs_controld to segfault when mounting hundreds of</li> file systems has been fixed.<br><li> the LPAR fencing agent now properly reports status when an LPAR is in</li> Open Firmware mode.<br><li> the LPAR fencing agent now works properly with systems using the</li> Integrated Virtualization Manager (IVM).<br><li> the APC SNMP fencing agent now properly recognizes outletStatusOn and</li> outletStatusOff return codes from the SNMP agent.<br><li> the WTI fencing agent can now connect to fencing devices with no</li> password.<br><li> the rps-10 fencing agent now properly performs a reboot when run with no</li> options.<br><li> the IPMI fencing agent now supports different cipher types with the '-C'</li> option.<br><li> qdisk now properly scans devices and partitions.</li> <li> cman now checks to see if a new node has state to prevent killing the</li> first node during cluster setup.<br><li> 'service qdiskd start' now works properly.</li> <li> the McData fence agent now works properly with the McData Sphereon 4500</li> Fabric Switch.<br><li> the Egenera fence agent can now specify an SSH login name.</li> <li> the APC fence agent now works with non-admin accounts when using the</li> 3.5.x firmware.<br><li> fence_xvmd now tries two methods to reboot a virtual machine.</li> <li> connections to OpenAIS are now allowed from unprivileged CPG clients with</li> the user and group of 'ais'.<br><li> groupd no longer allows the default fence domain to be '0', which</li> previously caused rgmanager to hang. Now, rgmanager no longer hangs.<br><li> the RSA fence agent now supports SSH enabled RSA II devices.</li> <li> the DRAC fence agent now works with the Integrated Dell Remote Access</li> Controller (iDRAC) on Dell PowerEdge M600 blade servers.<br><li> fixed a memory leak in cman.</li> <li> qdisk now displays a warning if more than one label is found with the</li> same name.<br><li> the DRAC5 fencing agent now shows proper usage instructions for the '-D'</li> option.<br><li> cman no longer uses the wrong node name when getnameinfo() fails.</li> <li> the SCSI fence agent now verifies that sg_persist is installed.</li> <li> the DRAC5 fencing agent now properly handles modulename.</li> <li> QDisk now logs warning messages if it appears its I/O to shared storage</li> is hung.<br><li> fence_apc no longer fails with a pexpect exception.</li> <li> removing a node from the cluster using 'cman_tool leave remove' now</li> properly reduces the expected_votes and quorum.<br><li> a semaphore leak in cman has been fixed.</li> <li> 'cman_tool nodes -F name' no longer segfaults when a node is out of</li> membership.<br>Enhancements:<br><li> support for: ePowerSwitch 8+ and LPAR/HMC v3 devices, Cisco MDS 9124 and</li> MDS 9134 SAN switches, the virsh fencing agent, and broadcast communication<br>with cman.<br><li> fence_scsi limitations added to fence_scsi man page.</li> Users of cman are advised to upgrade to these updated packages, which<br>resolve these issues and add these enhancements.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cman | <2.0.115-1.el5 | 2.0.115-1.el5 |
redhat/cman | <2.0.115-1.el5 | 2.0.115-1.el5 |
redhat/cman-devel | <2.0.115-1.el5 | 2.0.115-1.el5 |
redhat/cman-devel | <2.0.115-1.el5 | 2.0.115-1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.