[RHSA-2024:5338] pcs security update
Severity
Low
Affected Packages
8
CVEs
1
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.
Security Fix(es):
- REXML: DoS parsing an XML with many
<
s in an attribute value (CVE-2024-35176)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/pcs?arch=x86_64&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
pkg:rpm/redhat/pcs?arch=s390x&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
pkg:rpm/redhat/pcs?arch=ppc64le&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
pkg:rpm/redhat/pcs?arch=aarch64&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
pkg:rpm/redhat/pcs-snmp?arch=x86_64&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
pkg:rpm/redhat/pcs-snmp?arch=s390x&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
pkg:rpm/redhat/pcs-snmp?arch=ppc64le&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
pkg:rpm/redhat/pcs-snmp?arch=aarch64&distro=redhat-8.10 | < 0.10.18-2.el8_10.1 |
- ID
- RHSA-2024:5338
- Severity
- low
- URL
- https://access.redhat.com/errata/RHSA-2024:5338
- Published
-
2024-08-13T00:00:00
(4 weeks ago) - Modified
-
2024-08-13T00:00:00
(4 weeks ago) - Rights
- Copyright 2024 Red Hat, Inc.
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 2280894 | https://bugzilla.redhat.com/2280894 | |
RHSA | RHSA-2024:5338 | https://access.redhat.com/errata/RHSA-2024:5338 | |
CVE | CVE-2024-35176 | https://access.redhat.com/security/cve/CVE-2024-35176 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/pcs?arch=x86_64&distro=redhat-8.10 | redhat | pcs | < 0.10.18-2.el8_10.1 | redhat-8.10 | x86_64 | |
Affected | pkg:rpm/redhat/pcs?arch=s390x&distro=redhat-8.10 | redhat | pcs | < 0.10.18-2.el8_10.1 | redhat-8.10 | s390x | |
Affected | pkg:rpm/redhat/pcs?arch=ppc64le&distro=redhat-8.10 | redhat | pcs | < 0.10.18-2.el8_10.1 | redhat-8.10 | ppc64le | |
Affected | pkg:rpm/redhat/pcs?arch=aarch64&distro=redhat-8.10 | redhat | pcs | < 0.10.18-2.el8_10.1 | redhat-8.10 | aarch64 | |
Affected | pkg:rpm/redhat/pcs-snmp?arch=x86_64&distro=redhat-8.10 | redhat | pcs-snmp | < 0.10.18-2.el8_10.1 | redhat-8.10 | x86_64 | |
Affected | pkg:rpm/redhat/pcs-snmp?arch=s390x&distro=redhat-8.10 | redhat | pcs-snmp | < 0.10.18-2.el8_10.1 | redhat-8.10 | s390x | |
Affected | pkg:rpm/redhat/pcs-snmp?arch=ppc64le&distro=redhat-8.10 | redhat | pcs-snmp | < 0.10.18-2.el8_10.1 | redhat-8.10 | ppc64le | |
Affected | pkg:rpm/redhat/pcs-snmp?arch=aarch64&distro=redhat-8.10 | redhat | pcs-snmp | < 0.10.18-2.el8_10.1 | redhat-8.10 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |