Bug 1007433 (CVE-2016-7035) - VUL-0: CVE-2016-7035: pacemaker: improper IPC guarding
Summary: VUL-0: CVE-2016-7035: pacemaker: improper IPC guarding
Status: RESOLVED FIXED
: 1009037 (view as bug list)
Alias: CVE-2016-7035
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Yan Gao
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:SUSE:CVE-2016-7035:6.8:(AV:L/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-10-28 07:36 UTC by Alexander Bergmann
Modified: 2018-12-16 23:47 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2016-10-28 22:00:37 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2016-11-07 15:47:42 UTC
is public now 
http://www.openwall.com/lists/oss-security/2016/11/03/5


Date: Thu, 3 Nov 2016 11:34:35 +0100
From: Jan Pokorný <jpokorny@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2016-7035 - pacemaker - improper IPC guarding

Following issue is being publicly disclosed today:

A vulnerability has been found in pacemaker, a software package for
high-availability clustering.

It was discovered that at some not so uncommon circumstances, some
pacemaker daemons could be talked to, via libqb-facilitated IPC, by
unprivileged clients due to flawed authorization decision.  Depending
on the capabilities of affected daemons, this might equip unauthorized
user with local privilege escalation or up to cluster-wide remote
execution of possibly arbitrary commands when such user happens to
reside at standard or remote/guest cluster node, respectively.

The original vulnerability was introduced in an attempt to allow
unprivileged IPC clients to clean up the file system materialized
leftovers in case the server (otherwise responsible for the lifecycle
of these files) crashes.  While the intended part of such behavior is
now effectively voided (along with the unintended one), a best-effort
fix to address this corner case systemically at libqb is coming along
(https://github.com/ClusterLabs/libqb/pull/231).

Affected versions:  1.1.10-rc1 (2013-04-17) - 1.1.15 (2016-06-21)
Impact:             Important
CVSSv3 ranking:     8.8 : AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Credits for independent findings, in chronological order:
  Jan "poki" Pokorný, of Red Hat
  Alain Moulle, of ATOS/BULL


Patch for the issue, which is applicable on all affected versions:
https://github.com/ClusterLabs/pacemaker/pull/1166/commits/5a20855d6054ebaae590c09262b328d957cc1fc2

-- 
Jan (Poki)
Comment 5 Yan Gao 2016-11-15 11:57:44 UTC
*** Bug 1009037 has been marked as a duplicate of this bug. ***
Comment 6 Swamp Workflow Management 2016-11-22 14:04:27 UTC
SUSE-SU-2016:2869-1: An update that solves two vulnerabilities and has 5 fixes is now available.

Category: security (important)
Bug References: 1000743,1002767,1003565,1007433,967388,986644,987348
CVE References: CVE-2016-7035,CVE-2016-7797
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    pacemaker-1.1.15-21.1
SUSE Linux Enterprise High Availability 12-SP2 (src):    pacemaker-1.1.15-21.1
Comment 7 Swamp Workflow Management 2016-12-01 17:13:54 UTC
openSUSE-SU-2016:2965-1: An update that solves two vulnerabilities and has 5 fixes is now available.

Category: security (important)
Bug References: 1000743,1002767,1003565,1007433,967388,986644,987348
CVE References: CVE-2016-7035,CVE-2016-7797
Sources used:
openSUSE Leap 42.2 (src):    pacemaker-1.1.15-5.1
Comment 8 Swamp Workflow Management 2016-12-02 15:12:34 UTC
SUSE-SU-2016:2974-1: An update that solves two vulnerabilities and has 7 fixes is now available.

Category: security (moderate)
Bug References: 1000743,1002767,1003565,1007433,1009076,967388,986644,987348,995365
CVE References: CVE-2016-7035,CVE-2016-7797
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    pacemaker-1.1.13-20.1
SUSE Linux Enterprise High Availability 12-SP1 (src):    pacemaker-1.1.13-20.1
Comment 9 Swamp Workflow Management 2016-12-12 18:15:36 UTC
openSUSE-SU-2016:3101-1: An update that solves two vulnerabilities and has 7 fixes is now available.

Category: security (moderate)
Bug References: 1000743,1002767,1003565,1007433,1009076,967388,986644,987348,995365
CVE References: CVE-2016-7035,CVE-2016-7797
Sources used:
openSUSE Leap 42.1 (src):    pacemaker-1.1.13-23.2
Comment 10 Swamp Workflow Management 2016-12-15 17:09:08 UTC
SUSE-SU-2016:3162-1: An update that solves two vulnerabilities and has 23 fixes is now available.

Category: security (moderate)
Bug References: 1000743,1002767,1003565,1007433,1009076,953192,970733,971129,972187,974108,975079,976271,976865,977258,977675,977800,981489,981731,986056,986201,986265,986644,986676,986931,987348
CVE References: CVE-2016-7035,CVE-2016-7797
Sources used:
SUSE Linux Enterprise High Availability Extension 11-SP4 (src):    pacemaker-1.1.12-18.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    pacemaker-1.1.12-18.1
Comment 11 Johannes Segitz 2018-02-14 12:58:31 UTC
fixed