Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in dracut
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in dracut
ID: FEDORA-2012-14959
Distribution: Fedora
Plattformen: Fedora 16
Datum: Sa, 13. Oktober 2012, 10:32
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4453
Applikationen: dracut

Originalnachricht

Name        : dracut
Product : Fedora 16
Version : 018
Release : 60.git20120927.fc16
URL : https://dracut.wiki.kernel.org/
Summary : Initramfs generator using udev
Description :
Dracut contains tools to create a bootable initramfs for 2.6 Linux kernels.
Unlike existing implementations, dracut does hard-code as little as possible
into the initramfs. Dracut contains various modules which are driven by the
event-based udev. Having root on MD, DM, LVM2, LUKS is supported as well as
NFS, iSCSI, NBD, FCoE with the dracut-network package.

-------------------------------------------------------------------------------
-
Update Information:

dracut-018-60.git20120927
- run dracut-shutdown.service before shutdown.target
Resolves: rhbz#840120
- do not create the initramfs world readable
Resolves: rhbz#859448
- mdraid: do the dracut shutdown, if a md raid is found
- mdraid: handle nested md raids
- mdraid: wait until devices are clean on shutdown
Resolves: rhbz#732297 rhbz#840562

-------------------------------------------------------------------------------
-
ChangeLog:

* Thu Sep 27 2012 Harald Hoyer <harald@redhat.com> 018-60.git20120927
- run dracut-shutdown.service before shutdown.target
Resolves: rhbz#840120
- do not create the initramfs world readable
Resolves: rhbz#859448
- mdraid: do the dracut shutdown, if a md raid is found
- mdraid: handle nested md raids
- mdraid: wait until devices are clean on shutdown
Resolves: rhbz#732297 rhbz#840562
* Wed Jun 6 2012 Harald Hoyer <harald@redhat.com> 018-55.git20120606
- update to F17 version
- support for /usr mounting in the initramfs
- better hostonly support
- faster image creation
* Mon Mar 26 2012 Harald Hoyer <harald@redhat.com> 013-22
- added convertfs dracut module
- added mdraid --offroot support
* Mon Jan 23 2012 Harald Hoyer <harald@redhat.com> 013-21
- include /lib/modules/$(uname -r)/modules.order
* Tue Dec 13 2011 Harald Hoyer <harald@redhat.com> 013-20
- do not wait for raid to be synced
Resolves: rhbz#757361
* Thu Nov 17 2011 Harald Hoyer <harald@redhat.com> 013-19
- fixed mdraid handling
Resolves: rhbz#751667
- fix cdrom polling
- support opening crypto devs with file
support install_items in dracut.conf
Resolves: rhbz#751640
- include usb storage drivers
Resolves: rhbz#716799
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #859448 - CVE-2012-4453 dracut: Creates initramfs images with
world-readable permissions (information disclosure)
https://bugzilla.redhat.com/show_bug.cgi?id=859448
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update dracut' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung