From Mageia wiki
Jump to: navigation, search

MGASA-2012-0277

Date: September 30th, 2012
Affected releases: 1, 2


Description:
Updated ganglia packages fix security vulnerability:

There is a security issue in Ganglia Web going back to at least 3.1.7
which can lead to arbitrary script being executed with web user
privileges possibly leading to a machine compromise.

Additionally, an issue where active NFS mounts caused gmond to not
start has also been corrected.


Updated Packages:
Mageia 1:
ganglia-core-3.1.7-5.1.mga1
ganglia-gmetad-3.1.7-5.1.mga1
ganglia-script-3.1.7-5.1.mga1
ganglia-webfrontend-3.1.7-5.1.mga1
lib(64)ganglia1-3.1.7-5.1.mga1
lib(64)ganglia1-devel-3.1.7-5.1.mga1

Mageia 2:
ganglia-core-3.1.7-7.1.mga2
ganglia-gmetad-3.1.7-7.1.mga2
ganglia-script-3.1.7-7.1.mga2
ganglia-webfrontend-3.1.7-7.1.mga2
lib(64)ganglia1-3.1.7-7.1.mga2
lib(64)ganglia1-devel-3.1.7-7.1.mga2


References:
http://ganglia.info/?p=549
https://bugs.launchpad.net/ubuntu/+source/ganglia/+bug/910678
http://lists.fedoraproject.org/pipermail/package-announce/2012-July/084202.html
https://bugs.mageia.org/show_bug.cgi?id=6874