========================================================================== Ubuntu Security Notice USN-3462-1 October 24, 2017 pacemaker vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Pacemaker. Software Description: - pacemaker: Cluster resource manager Details: Jan PokornA1/2 and Alain Moulle discovered that Pacemaker incorrectly handled the IPC interface. A local attacker could possibly use this issue to execute arbitrary code with root privileges. (CVE-2016-7035) Alain Moulle discovered that Pacemaker incorrectly handled authentication. A remote attacker could possibly use this issue to shut down connections, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-7797) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: pacemaker 1.1.14-2ubuntu1.2 Ubuntu 14.04 LTS: pacemaker 1.1.10+git20130802-1ubuntu2.4 In general, a standard system update will make all the necessary changes. References: https://www.ubuntu.com/usn/usn-3462-1 CVE-2016-7035, CVE-2016-7797 Package Information: https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2 https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4