Sicherheit: Preisgabe von Informationen in dracut
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in dracut
ID: FEDORA-2012-14953
Distribution: Fedora
Plattformen: Fedora 17
Datum: Sa, 13. Oktober 2012, 10:32
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4453
Applikationen: dracut


Name        : dracut
Product : Fedora 17
Version : 018
Release : 105.git20120927.fc17
URL : https://dracut.wiki.kernel.org/
Summary : Initramfs generator using udev
Description :
Dracut contains tools to create a bootable initramfs for 2.6 Linux kernels.
Unlike existing implementations, dracut does hard-code as little as possible
into the initramfs. Dracut contains various modules which are driven by the
event-based udev. Having root on MD, DM, LVM2, LUKS is supported as well as
NFS, iSCSI, NBD, FCoE with the dracut-network package.

Update Information:

- enable the use of the nbd port with e.g. '-N ltsp'
- actually make reset_overlay working for squash overlays
- fixed FIPS
- if any mdraid found, make dracut run on shutdown
- make the initramfs non-world readable

* Thu Sep 27 2012 Harald Hoyer <harald@redhat.com> 018-105.git20120927
- enable the use of the nbd port with e.g. '-N ltsp'
- actually make reset_overlay working for squash overlays
- fixed FIPS
- if any mdraid found, make dracut run on shutdown
- make the initramfs non-world readable
* Mon Aug 13 2012 Harald Hoyer <harald@redhat.com> 018-98.git20120813
- fixed keymap include issues
Resolves: rhbz#845744
* Wed Aug 1 2012 Dennis Gilmore <dennis@ausil.us> 018-97.git20120724
- include omap_hsmmc on arm
* Tue Jul 24 2012 Harald Hoyer <harald@redhat.com> 018-96.git20120724
- fixed some more race condition in resume
* Fri Jul 20 2012 Harald Hoyer <harald@redhat.com> 018-95.git20120720
- fixed some more race condition in resume
* Thu Jul 19 2012 Harald Hoyer <harald@redhat.com> 018-93.git20120719
- do not rename network interfaces
- wait until md raids are clean on shutdown
- fips module fixes
- fixed BOOTIF case sensitive
- fixed resume from hibernate
- nfs module fixes
* Fri Jun 22 2012 Harald Hoyer <harald@redhat.com> 018-78.git20120622
- speedup install
- fixed installkernel() return codes
- removed test mounting of btrfs and xfs (was fsck replacement)
- no more "mknod" in the initramfs, fixes plymouth on s390
- no systemd-vconsole-setup installation (unused currently anyway)
* Fri Jun 22 2012 Harald Hoyer <harald@redhat.com> 018-67.git20120622
- add tagged bonding
Resolves: rhbz#833057
- fixed shutdown service
Resolves: rhbz#831634
* Tue Jun 12 2012 Harald Hoyer <harald@redhat.com> 018-65.git20120612
- revert to "ip=dhcp" by default
* Mon Jun 11 2012 Harald Hoyer <harald@redhat.com> 018-55.git20120611
- default to dhcp for BOOTIF
* Tue Jun 5 2012 Dennis Gilmore <dennis@ausil.us> 018-53.git20120605
- include omapdrm in the arm modules to include
* Tue Jun 5 2012 Harald Hoyer <harald@redhat.com> 018-52.git20120605
- change rd.dasd to dasd_mod kernel parameter
* Mon Jun 4 2012 Harald Hoyer <harald@redhat.com> 018-51.git20120604
- fix network rules for kdump
Resolves: rhbz#822750
- disable curl progress bar
Resolves: rhbz#817301 rhbz#824883
- do not default to dhcp for interfaces without ip=
- do not arping with qeth layer3 interfaces
Resolves: rhbz#825783
- do not unpack the initramfs, if the old initramfs still exists
- add rd.luks.allow-discards and honor options in crypttab
- fixed dasd_mod param generation
- fix return value of some installkernel() functions
- do not rely on the presence of lib64, check with ldd
- dasd: don't set an already set attribute
Resolves: rhbz#826357
- add filesystem options to fsck_single()
* Tue May 22 2012 Harald Hoyer <harald@redhat.com> 018-40.git20120522
- fixed s390 dasd handling
- fixed DNS bug for s390
* Thu May 17 2012 Dennis Gilmore <dennis@ausil.us> 018-36.git20120510
- add patch for arm storage modules

[ 1 ] Bug #859448 - CVE-2012-4453 dracut: Creates initramfs images with
world-readable permissions (information disclosure)

This update can be installed with the "yum" update program. Use
su -c 'yum update dracut' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Neue Nachrichten