[Apollo] Advisories Red Hat Advisories Statistics light light Login

RHSA-2022:7935

Security
Issued at: 2022-11-15
launch
Open original
Override

Synopsis

Moderate: pcs security, bug fix, and enhancement update



Description

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

* pcs: improper authentication via PAM (CVE-2022-1049)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section.



Affected products

Red Hat Enterprise Linux for ARM 64 - 9 Red Hat Enterprise Linux for IBM z Systems - 9 Red Hat Enterprise Linux for Power, little endian - 9 Red Hat Enterprise Linux for x86_64 - 9

Fixes

2066629

CVEs

CVE-2022-1049

Affected packages

pcs-0:0.11.3-4.el9.aarch64 pcs-0:0.11.3-4.el9.ppc64le pcs-0:0.11.3-4.el9.s390x pcs-0:0.11.3-4.el9.src pcs-0:0.11.3-4.el9.x86_64 pcs-snmp-0:0.11.3-4.el9.aarch64 pcs-snmp-0:0.11.3-4.el9.ppc64le pcs-snmp-0:0.11.3-4.el9.s390x pcs-snmp-0:0.11.3-4.el9.x86_64