Executive Summary

Summary
Title conga security, bug fix, and enhancement update
Informations
Name RHSA-2007:0983 First vendor Publication 2007-11-21
Vendor RedHat Last vendor Modification 2007-11-21
Severity (Vendor) Moderate Revision 01

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

Updated conga packages that fix a security flaw, several bugs, and add enhancements are now available for Red Hat Cluster Suite.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Cluster Suite 4AS - i386, ia64, x86_64 Red Hat Cluster Suite 4ES - i386, ia64, x86_64 Red Hat Cluster Suite 4WS - i386, ia64, x86_64

3. Problem description:

The Conga package is a web-based administration tool for remote cluster and storage management.

A flaw was found in ricci during a code audit. A remote attacker who is able to connect to ricci could cause ricci to temporarily refuse additional connections, resulting in a denial of service. (CVE-2007-4136)

Additionally, these updated packages fix the following bugs:

* entering an invalid password when creating a new cluster with the luci web application caused a "UnboundLocalError" error.

* conga did not set the the "nodename" attribute for instances of manual fencing, resulting in manual fencing being non-functional.

* conga did not provide a way to remove a dead node from a cluster. Attempting to remove a dead node from a cluster resulted in an error, reporting that that the node name cannot be reached.

* during cluster formation Conga reboots the cluster nodes. During reboot errors about not being able to communicate with nodes are displayed. These errors can safely be ignored, and have been removed in these updated packages.

* when building a new cluster on Red Hat Enterprise Linux 4, Conga did not generate node ID attributes for clusternode tags. The node ID attributes are needed by programs such as qdisk.

* during Quorum Partition Configuration, a "TypeError" error occurred if you did not configure heuristics.

* when passing arguments to fence_scsi, Conga used the "nodename" attribute instead of the "node" attribute, resulting in an invalid XML file being passed to fence_scsi. The "nodename" attribute is now supported.

* conga did not handle the restart operation correctly. In certain situations this resulted in nodes not being started, stopped, and restarted correctly. These issues were caused by clusters starting while others were still in the process of stopping. This has been resolved in these updated packages.

* probing storage using luci and the Mozilla Firefox 2 web browser on Microsoft Windows XP appeared to never finish, when in fact it had. After probing, clicking the node name in the storage list correctly showed the storage for that node.

As well, these updated packages add the following enhancements:

* the Conga web interface now supports the Microsoft Internet Explorer web browser, versions 6.0 and later.

* in previous packages, Conga required a minimum score to be configured even when heuristics were not being used. A minimum score is no longer required.

All Conga users are advised to upgrade to these updated packages, which fix this vulnerability, resolve these issues, and add these enhancements.

4. Solution:

Before applying this update, make sure that all previously-released errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at http://kbase.redhat.com/faq/FAQ_58_10188

5. Bug IDs fixed (http://bugzilla.redhat.com/):

227723 - Entering bad password when creating a new cluster = UnboundLocalError: local variable 'e' referenced before assignment 238656 - conga does not set the "nodename" attribute for manual fencing 238727 - Conga provides no way to remove a dead node from a cluster 241414 - Installation using Conga shows "error" in message during reboot cycle. 245200 - Conga needs to support Internet Explorer 6.0 and later 253901 - No node IDs generated on new RHEL4 / DLM cluster 253905 - Quorum disk page: Minimum score does not need to be required 253906 - Quorum disk page: Error when trying to continue w/o a heuristic 286951 - conga passes fence_scsi nodename, where as it accepts only node 325501 - conga doesn't handle the cluster restart operation properly 336101 - CVE-2007-4136 ricci is vulnerable to a connect DoS attack 340101 - Storage redirection after probe does not work on WinXP with FF2

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2007-0983.html

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:22686
 
Oval ID: oval:org.mitre.oval:def:22686
Title: ELSA-2007:0640: conga security, bug fix, and enhancement update (Moderate)
Description: The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.
Family: unix Class: patch
Reference(s): ELSA-2007:0640-05
CVE-2007-4136
Version: 6
Platform(s): Oracle Linux 5
Product(s): conga
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:9871
 
Oval ID: oval:org.mitre.oval:def:9871
Title: The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.
Description: The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.
Family: unix Class: vulnerability
Reference(s): CVE-2007-4136
Version: 5
Platform(s): Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Open Source Vulnerability Database (OSVDB)

Id Description
39853 Red Hat Conga ricci Daemon New Connection Saturation Remote DoS

Nessus® Vulnerability Scanner

Date Description
2013-01-24 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2007-0640.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20071107_conga_on_SL5_x.nasl - Type : ACT_GATHER_INFO