UbuntuUpdates.org

Package "crmsh"

Name: crmsh

Description:

CRM shell for the pacemaker cluster manager

Latest version: 4.2.0-2ubuntu1.1
Release: focal (20.04)
Level: security
Repository: main
Homepage: http://crmsh.github.io/

Links


Download "crmsh"


Other versions of "crmsh" in Focal

Repository Area Version
base main 4.2.0-2ubuntu1
updates main 4.2.0-2ubuntu1.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 4.2.0-2ubuntu1.1 2024-03-25 15:06:53 UTC

  crmsh (4.2.0-2ubuntu1.1) focal-security; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2020-35459.patch: using
      Path.mkdir instead mkdir command in crmsh/history.py,
      crmsh/utils.py.
    - CVE-2020-35459

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 19 Mar 2024 13:35:12 -0300

CVE-2020-35459 An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute comma



About   -   Send Feedback to @ubuntu_updates