Red Hat Security Advisory 2019-1352-01 - The etcd packages provide a highly available key-value store for shared configuration. An improper authentication vulnerability was addressed.
27e8b6a282e53e9ccfe93c516b662721ff77aa483599cc1fe1327f241578baf6
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: etcd security, bug fix, and enhancement update
Advisory ID: RHSA-2019:1352-01
Product: Red Hat Enterprise Linux Extras
Advisory URL: https://access.redhat.com/errata/RHSA-2019:1352
Issue date: 2019-06-04
CVE Names: CVE-2018-16886
====================================================================
1. Summary:
An update for etcd is now available for Red Hat Enterprise Linux 7 Extras.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux 7 Extras - aarch64, ppc64le, s390x, x86_64
3. Description:
The etcd packages provide a highly available key-value store for shared
configuration.
The following packages have been upgraded to a later upstream version: etcd
(3.2.26). (BZ#1676902)
Security Fix(es):
* etcd: Improper Authentication in auth/store.go:AuthInfoFromTLS() via
gRPC-gateway (CVE-2018-16886)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
1651034 - CVE-2018-16886 etcd: Improper Authentication in auth/store.go:AuthInfoFromTLS() via gRPC-gateway
1676902 - Update etcd to the latest relevant upstream for AH 7.6.2
6. Package List:
Red Hat Enterprise Linux 7 Extras:
Source:
etcd-3.2.26-1.el7.src.rpm
aarch64:
etcd-3.2.26-1.el7.aarch64.rpm
etcd-debuginfo-3.2.26-1.el7.aarch64.rpm
ppc64le:
etcd-3.2.26-1.el7.ppc64le.rpm
etcd-debuginfo-3.2.26-1.el7.ppc64le.rpm
s390x:
etcd-3.2.26-1.el7.s390x.rpm
etcd-debuginfo-3.2.26-1.el7.s390x.rpm
Red Hat Enterprise Linux 7 Extras:
Source:
etcd-3.2.26-1.el7.src.rpm
aarch64:
etcd-3.2.26-1.el7.aarch64.rpm
etcd-debuginfo-3.2.26-1.el7.aarch64.rpm
ppc64le:
etcd-3.2.26-1.el7.ppc64le.rpm
etcd-debuginfo-3.2.26-1.el7.ppc64le.rpm
s390x:
etcd-3.2.26-1.el7.s390x.rpm
etcd-debuginfo-3.2.26-1.el7.s390x.rpm
x86_64:
etcd-3.2.26-1.el7.x86_64.rpm
etcd-debuginfo-3.2.26-1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2018-16886
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBXPbCTNzjgjWX9erEAQgDYBAAhXvI4zyrTDBWXpkOj6scp/MzGUVUKCA6
3BzZHxiIduJmPSo/FYU2l2nUpApqatVB7Vn5LSvzTSsH38hBMHxTz5mIwJ87GYdJ
uqmKu+XYx2UPjIGbGXWIdTDttcJ0uoP8/pbnL6YVXl2uKqELLU8iqgtFTn/D00fv
1OF+HvGKKEpoUjLLz81X5Pmz+Je9484RnHa2r2DyMoHqR52InWZbl+t6Acp02AAU
0O6zgPYZJhmgtK4wZDC7YnMtAIsM92qfWKywgnCzqNYdx/vB4/TTEBzf48G+RdYm
Q49zH1S8aSn6+LX0nrqOkf748+S+vsFt1Q07IhgtrrfbgX65LlkD4Z3xu4/Fm426
XWFehcjeU+3Nr1jxXZKzOZqcC1XbCH3hzBl3oBMEM19fPuJwpLeTglOQjDdncLNp
e5nYu/PkN/otgJyWsG0lSCm036xHyP+saRxTKFsTedXgaaZs6zp/qLLadprqoq+S
1sRC9lqHNiHjLfh6YRwGZex8Z48SAdKPym+lMic52rEw33d7MSAPbgKS334rJsGH
pdJ8dZSI2FOL3bQbO/Soo4To9JL8q7Q8CvbJokjHgSxHc00Z9C/ypO59lGTExWNc
rCuwFeKPIuPRk78ESUEo1HnL/HYSUXYLv2jqcVg+i+xJyJN9uqRX2BQAmaIQnK3/
SzXNnop2CH8=EQFo
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce