Revision Date: | 2014-05-26 | Version: | 13 | Title: | ELSA-2011:1000: rgmanager security, bug fix, and enhancement update (Low) | Description: | The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | Family: | unix | Class: | patch | Status: | ACCEPTED | Reference(s): | CVE-2010-3389 ELSA-2011:1000-01
| Platform(s): | Oracle Linux 5
| Product(s): | rgmanager
| Definition Synopsis | Oracle Linux 5.x AND rgmanager is earlier than 0:2.0.52-21.el5
|
|