-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: Red Hat CloudForms Management Engine security update Advisory ID: RHSA-2013:1206-01 Product: Red Hat CloudForms Advisory URL: https://rhn.redhat.com/errata/RHSA-2013-1206.html Issue date: 2013-09-04 CVE Names: CVE-2013-2068 ===================================================================== 1. Summary: The RHSA-2013:1157 update for Red Hat CloudForms Management Engine included an additional fix that was not documented in the erratum. The Red Hat Security Response Team has rated this update as having critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Description: Red Hat CloudForms Management Engine provides the insight, control, and automation needed to address the challenges of managing virtual environments. Multiple directory traversal flaws were found in Red Hat CloudForms Management Engine. A remote, unauthenticated attacker could use these flaws to upload arbitrary code, and have that code executed with root privileges on Red Hat CloudForms Management Engine. (CVE-2013-2068) This issue was discovered by Ramon de C Valle of the Red Hat Product Security Team. Note: This issue was already addressed in the fixpack released as part of RHSA-2013:1157, however it was not documented and therefore the erratum was incorrectly rated as having important security impact. No new packages are available in this erratum; please install the fixpack as noted in RHSA-2013:1157. Refer to the Solution section of this erratum for installation instructions. 3. Solution: The update is provided in a fixpack, available from: https://rhn.redhat.com/rhn/software/channel/downloads/Download.do?cid=17971 To install the fixpack, follow the instructions in the following Red Hat Knowledge Base article: https://access.redhat.com/site/articles/450563 4. Bugs fixed (http://bugzilla.redhat.com/): 960422 - CVE-2013-2068 CFME 2.0 multiple zip file upload path traversal vulnerabilities 5. References: https://www.redhat.com/security/data/cve/CVE-2013-2068.html https://access.redhat.com/security/updates/classification/#critical https://access.redhat.com/site/articles/450563 https://access.redhat.com/site/documentation/en-US/CloudForms/2.0/html/Management_Engine_5.1_Technical_Notes/index.html https://rhn.redhat.com/errata/RHSA-2013-1157.html 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2013 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFSJ4PGXlSAg2UNWIIRAtzcAKCa4rEE/P0NvPF/rhY6vlwl81XpKACeIiue OSljXQiKwn6Pwlevj2DnpWU= =UTMt -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce