RHSA-2011:0393: Important: conga security update
The conga packages provide a web-based administration tool for remotecluster and storage management.A privilege escalation flaw was found in luci, the Conga web-basedadministration application. A remote attacker could possibly use this flawto obtain administrative access, allowing them to read, create, or modifythe content of the luci application. (CVE-2011-0720)Users of Conga are advised to upgrade to these updated packages, whichcontain a backported patch to resolve this issue. After installing theupdated packages, luci must be restarted ("service luci restart") for theupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:0393?
The severity of RHSA-2011:0393 is classified as important.
How do I fix RHSA-2011:0393?
To fix RHSA-2011:0393, update the conga packages to the latest version provided by the vendor.
What type of vulnerability is described in RHSA-2011:0393?
RHSA-2011:0393 describes a privilege escalation vulnerability in the Luci web-based administration application.
Who is affected by RHSA-2011:0393?
The vulnerability in RHSA-2011:0393 affects users of the conga web-based administration tool for remote cluster and storage management.
Can RHSA-2011:0393 be exploited remotely?
Yes, a remote attacker could exploit the vulnerability described in RHSA-2011:0393 to obtain administrative access.