[SECURITY] Fedora 17 Update: openvswitch-1.4.2-5.fc17
updates at fedoraproject.org
updates at fedoraproject.org
Tue Nov 13 00:55:16 UTC 2012
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-17477
2012-11-02 02:59:37
--------------------------------------------------------------------------------
Name : openvswitch
Product : Fedora 17
Version : 1.4.2
Release : 5.fc17
URL : http://openvswitch.org
Summary : Open vSwitch daemon/database/utilities
Description :
Open vSwitch provides standard network bridging functions and
support for the OpenFlow protocol for remote per-flow control of
traffic.
--------------------------------------------------------------------------------
Update Information:
Don't create world writable pki/*/incoming directory
Don't add iptables accept rule for -p GRE as GRE tunneling is unsupported
--------------------------------------------------------------------------------
ChangeLog:
* Thu Nov 1 2012 Thomas Graf <tgraf at redhat.com> - 1.4.2-5
- Don't create world writable pki/*/incoming directory (#845351)
* Thu Oct 25 2012 Thomas Graf <tgraf at redhat.com> - 1.4.2-4
- Don't add iptables accept rule for -p GRE as GRE tunneling is unsupported
* Wed Oct 10 2012 Thomas Graf <tgraf at redhat.com> - 1.4.2-3
- make ovs-vsctl timeout if daemon is not running (#858722)
* Mon Sep 10 2012 Thomas Graf <tgraf at redhat.com> - 1.4.2-2
- add controller package containing ovs-controller
* Fri Aug 17 2012 Tomas Hozza <thozza at redhat.com> - 1.4.2-1
- Update to 1.4.2
- Fixed openvswitch-rhel-initscripts-resync.patch so it fits on new sources.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #845351 - CVE-2012-3449 openvswitch: creates world writable directories: /var/lib/openvswitch/pki/*ca/incoming/ [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=845351
[ 2 ] Bug #870034 - openvswitch: iptables rule to let through GRE traffic is added even though GRE is unsupported
https://bugzilla.redhat.com/show_bug.cgi?id=870034
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update openvswitch' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
More information about the package-announce
mailing list