RHEL 7 : Red Hat Gluster Storage 3.2.0 (RHSA-2017:0486)

high Nessus Plugin ID 97929

Synopsis

The remote Red Hat host is missing a security update.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2017:0486 advisory.

Red Hat Gluster Storage is a software only scale-out storage solution that provides flexible and affordable unstructured data storage. It unifies data storage and infrastructure, increases performance, and improves availability and manageability to meet enterprise-level storage challenges.

The following packages have been upgraded to a later upstream version: glusterfs (3.8.4), redhat-storage- server (3.2.0.2), vdsm (4.17.33). (BZ#1362376)

Security Fix(es):

* It was found that glusterfs-server RPM package would write file with predictable name into world readable /tmp directory. A local attacker could potentially use this flaw to escalate their privileges to root by modifying the shell script during the installation of the glusterfs-server package.
(CVE-2015-1795)

This issue was discovered by Florian Weimer of Red Hat Product Security.

Bug Fix(es):

* Bricks remain stopped if server quorum is no longer met, or if server quorum is disabled, to ensure that bricks in maintenance are not started incorrectly. (BZ#1340995)

* The metadata cache translator has been updated to improve Red Hat Gluster Storage performance when reading small files. (BZ#1427783)

* The 'gluster volume add-brick' command is no longer allowed when the replica count has increased and any replica bricks are unavailable. (BZ#1404989)

* Split-brain resolution commands work regardless of whether client-side heal or the self-heal daemon are enabled. (BZ#1403840)

Enhancement(s):

* Red Hat Gluster Storage now provides Transport Layer Security support for Samba and NFS-Ganesha.
(BZ#1340608, BZ#1371475)

* A new reset-sync-time option enables resetting the sync time attribute to zero when required.
(BZ#1205162)

* Tiering demotions are now triggered at most 5 seconds after a hi-watermark breach event. Administrators can use the cluster.tier-query-limit volume parameter to specify the number of records extracted from the heat database during demotion. (BZ#1361759)

* The /var/log/glusterfs/etc-glusterfs-glusterd.vol.log file is now named /var/log/glusterfs/glusterd.log.
(BZ#1306120)

* The 'gluster volume attach-tier/detach-tier' commands are considered deprecated in favor of the new commands, 'gluster volume tier VOLNAME attach/detach'. (BZ#1388464)

* The HA_VOL_SERVER parameter in the ganesha-ha.conf file is no longer used by Red Hat Gluster Storage.
(BZ#1348954)

* The volfile server role can now be passed to another server when a server is unavailable. (BZ#1351949)

* Ports can now be reused when they stop being used by another service. (BZ#1263090)

* The thread pool limit for the rebalance process is now dynamic, and is determined based on the number of available cores. (BZ#1352805)

* Brick verification at reboot now uses UUID instead of brick path. (BZ#1336267)

* LOGIN_NAME_MAX is now used as the maximum length for the slave user instead of __POSIX_LOGIN_NAME_MAX, allowing for up to 256 characters including the NULL byte. (BZ#1400365)

* The client identifier is now included in the log message to make it easier to determine which client failed to connect. (BZ#1333885)

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?0461e51d

http://www.nessus.org/u?b5a22bf1

https://access.redhat.com/errata/RHSA-2017:0486

https://access.redhat.com/security/updates/classification/#moderate

https://bugzilla.redhat.com/show_bug.cgi?id=1168606

https://bugzilla.redhat.com/show_bug.cgi?id=1200927

https://bugzilla.redhat.com/show_bug.cgi?id=1205162

https://bugzilla.redhat.com/show_bug.cgi?id=1211845

https://bugzilla.redhat.com/show_bug.cgi?id=1240333

https://bugzilla.redhat.com/show_bug.cgi?id=1241314

https://bugzilla.redhat.com/show_bug.cgi?id=1245084

https://bugzilla.redhat.com/show_bug.cgi?id=1248998

https://bugzilla.redhat.com/show_bug.cgi?id=1256483

https://bugzilla.redhat.com/show_bug.cgi?id=1256524

https://bugzilla.redhat.com/show_bug.cgi?id=1257182

https://bugzilla.redhat.com/show_bug.cgi?id=1258267

https://bugzilla.redhat.com/show_bug.cgi?id=1263090

https://bugzilla.redhat.com/show_bug.cgi?id=1264310

https://bugzilla.redhat.com/show_bug.cgi?id=1278336

https://bugzilla.redhat.com/show_bug.cgi?id=1278385

https://bugzilla.redhat.com/show_bug.cgi?id=1278394

https://bugzilla.redhat.com/show_bug.cgi?id=1278900

https://bugzilla.redhat.com/show_bug.cgi?id=1284873

https://bugzilla.redhat.com/show_bug.cgi?id=1286038

https://bugzilla.redhat.com/show_bug.cgi?id=1286572

https://bugzilla.redhat.com/show_bug.cgi?id=1294035

https://bugzilla.redhat.com/show_bug.cgi?id=1296796

https://bugzilla.redhat.com/show_bug.cgi?id=1298118

https://bugzilla.redhat.com/show_bug.cgi?id=1299841

https://bugzilla.redhat.com/show_bug.cgi?id=1306120

https://bugzilla.redhat.com/show_bug.cgi?id=1306656

https://bugzilla.redhat.com/show_bug.cgi?id=1312199

https://bugzilla.redhat.com/show_bug.cgi?id=1315544

https://bugzilla.redhat.com/show_bug.cgi?id=1317653

https://bugzilla.redhat.com/show_bug.cgi?id=1318000

https://bugzilla.redhat.com/show_bug.cgi?id=1319078

https://bugzilla.redhat.com/show_bug.cgi?id=1319886

https://bugzilla.redhat.com/show_bug.cgi?id=1324053

https://bugzilla.redhat.com/show_bug.cgi?id=1325821

https://bugzilla.redhat.com/show_bug.cgi?id=1326066

https://bugzilla.redhat.com/show_bug.cgi?id=1327952

https://bugzilla.redhat.com/show_bug.cgi?id=1328451

https://bugzilla.redhat.com/show_bug.cgi?id=1332080

https://bugzilla.redhat.com/show_bug.cgi?id=1332133

https://bugzilla.redhat.com/show_bug.cgi?id=1332542

https://bugzilla.redhat.com/show_bug.cgi?id=1333406

https://bugzilla.redhat.com/show_bug.cgi?id=1333484

https://bugzilla.redhat.com/show_bug.cgi?id=1333749

https://bugzilla.redhat.com/show_bug.cgi?id=1333885

https://bugzilla.redhat.com/show_bug.cgi?id=1334664

https://bugzilla.redhat.com/show_bug.cgi?id=1334858

https://bugzilla.redhat.com/show_bug.cgi?id=1335029

https://bugzilla.redhat.com/show_bug.cgi?id=1336267

https://bugzilla.redhat.com/show_bug.cgi?id=1336339

https://bugzilla.redhat.com/show_bug.cgi?id=1336377

https://bugzilla.redhat.com/show_bug.cgi?id=1336764

https://bugzilla.redhat.com/show_bug.cgi?id=1337391

https://bugzilla.redhat.com/show_bug.cgi?id=1337444

https://bugzilla.redhat.com/show_bug.cgi?id=1337450

https://bugzilla.redhat.com/show_bug.cgi?id=1337477

https://bugzilla.redhat.com/show_bug.cgi?id=1337495

https://bugzilla.redhat.com/show_bug.cgi?id=1337565

https://bugzilla.redhat.com/show_bug.cgi?id=1337811

https://bugzilla.redhat.com/show_bug.cgi?id=1337836

https://bugzilla.redhat.com/show_bug.cgi?id=1337863

https://bugzilla.redhat.com/show_bug.cgi?id=1338615

https://bugzilla.redhat.com/show_bug.cgi?id=1338748

https://bugzilla.redhat.com/show_bug.cgi?id=1339159

https://bugzilla.redhat.com/show_bug.cgi?id=1340338

https://bugzilla.redhat.com/show_bug.cgi?id=1340608

https://bugzilla.redhat.com/show_bug.cgi?id=1340756

https://bugzilla.redhat.com/show_bug.cgi?id=1340995

https://bugzilla.redhat.com/show_bug.cgi?id=1341934

https://bugzilla.redhat.com/show_bug.cgi?id=1342459

https://bugzilla.redhat.com/show_bug.cgi?id=1343178

https://bugzilla.redhat.com/show_bug.cgi?id=1343320

https://bugzilla.redhat.com/show_bug.cgi?id=1343695

https://bugzilla.redhat.com/show_bug.cgi?id=1344322

https://bugzilla.redhat.com/show_bug.cgi?id=1344651

https://bugzilla.redhat.com/show_bug.cgi?id=1344675

https://bugzilla.redhat.com/show_bug.cgi?id=1344826

https://bugzilla.redhat.com/show_bug.cgi?id=1344908

https://bugzilla.redhat.com/show_bug.cgi?id=1345732

https://bugzilla.redhat.com/show_bug.cgi?id=1347251

https://bugzilla.redhat.com/show_bug.cgi?id=1347257

https://bugzilla.redhat.com/show_bug.cgi?id=1347625

https://bugzilla.redhat.com/show_bug.cgi?id=1347922

https://bugzilla.redhat.com/show_bug.cgi?id=1347923

https://bugzilla.redhat.com/show_bug.cgi?id=1348949

https://bugzilla.redhat.com/show_bug.cgi?id=1348954

https://bugzilla.redhat.com/show_bug.cgi?id=1348962

https://bugzilla.redhat.com/show_bug.cgi?id=1351589

https://bugzilla.redhat.com/show_bug.cgi?id=1351732

https://bugzilla.redhat.com/show_bug.cgi?id=1351825

https://bugzilla.redhat.com/show_bug.cgi?id=1351949

https://bugzilla.redhat.com/show_bug.cgi?id=1352125

https://bugzilla.redhat.com/show_bug.cgi?id=1352805

https://bugzilla.redhat.com/show_bug.cgi?id=1353427

https://bugzilla.redhat.com/show_bug.cgi?id=1354260

https://bugzilla.redhat.com/show_bug.cgi?id=1356058

https://bugzilla.redhat.com/show_bug.cgi?id=1356804

https://bugzilla.redhat.com/show_bug.cgi?id=1359180

https://bugzilla.redhat.com/show_bug.cgi?id=1359588

https://bugzilla.redhat.com/show_bug.cgi?id=1359605

https://bugzilla.redhat.com/show_bug.cgi?id=1359607

https://bugzilla.redhat.com/show_bug.cgi?id=1359619

https://bugzilla.redhat.com/show_bug.cgi?id=1360807

https://bugzilla.redhat.com/show_bug.cgi?id=1360978

https://bugzilla.redhat.com/show_bug.cgi?id=1361066

https://bugzilla.redhat.com/show_bug.cgi?id=1361068

https://bugzilla.redhat.com/show_bug.cgi?id=1361078

https://bugzilla.redhat.com/show_bug.cgi?id=1361082

https://bugzilla.redhat.com/show_bug.cgi?id=1361084

https://bugzilla.redhat.com/show_bug.cgi?id=1361086

https://bugzilla.redhat.com/show_bug.cgi?id=1361098

https://bugzilla.redhat.com/show_bug.cgi?id=1361101

https://bugzilla.redhat.com/show_bug.cgi?id=1361118

https://bugzilla.redhat.com/show_bug.cgi?id=1361155

https://bugzilla.redhat.com/show_bug.cgi?id=1361170

https://bugzilla.redhat.com/show_bug.cgi?id=1361184

https://bugzilla.redhat.com/show_bug.cgi?id=1361513

https://bugzilla.redhat.com/show_bug.cgi?id=1361519

https://bugzilla.redhat.com/show_bug.cgi?id=1362376

https://bugzilla.redhat.com/show_bug.cgi?id=1364422

https://bugzilla.redhat.com/show_bug.cgi?id=1364551

https://bugzilla.redhat.com/show_bug.cgi?id=1366128

https://bugzilla.redhat.com/show_bug.cgi?id=1367382

https://bugzilla.redhat.com/show_bug.cgi?id=1367472

https://bugzilla.redhat.com/show_bug.cgi?id=1369384

https://bugzilla.redhat.com/show_bug.cgi?id=1369391

https://bugzilla.redhat.com/show_bug.cgi?id=1370350

https://bugzilla.redhat.com/show_bug.cgi?id=1371475

https://bugzilla.redhat.com/show_bug.cgi?id=1373976

https://bugzilla.redhat.com/show_bug.cgi?id=1374166

https://bugzilla.redhat.com/show_bug.cgi?id=1375057

https://bugzilla.redhat.com/show_bug.cgi?id=1375465

https://bugzilla.redhat.com/show_bug.cgi?id=1376464

https://bugzilla.redhat.com/show_bug.cgi?id=1377062

https://bugzilla.redhat.com/show_bug.cgi?id=1377387

https://bugzilla.redhat.com/show_bug.cgi?id=1378030

https://bugzilla.redhat.com/show_bug.cgi?id=1378131

https://bugzilla.redhat.com/show_bug.cgi?id=1378300

https://bugzilla.redhat.com/show_bug.cgi?id=1378342

https://bugzilla.redhat.com/show_bug.cgi?id=1378484

https://bugzilla.redhat.com/show_bug.cgi?id=1378528

https://bugzilla.redhat.com/show_bug.cgi?id=1378676

https://bugzilla.redhat.com/show_bug.cgi?id=1378677

https://bugzilla.redhat.com/show_bug.cgi?id=1378867

https://bugzilla.redhat.com/show_bug.cgi?id=1379241

https://bugzilla.redhat.com/show_bug.cgi?id=1379919

https://bugzilla.redhat.com/show_bug.cgi?id=1379924

https://bugzilla.redhat.com/show_bug.cgi?id=1379963

https://bugzilla.redhat.com/show_bug.cgi?id=1379966

https://bugzilla.redhat.com/show_bug.cgi?id=1380122

https://bugzilla.redhat.com/show_bug.cgi?id=1380257

https://bugzilla.redhat.com/show_bug.cgi?id=1380276

https://bugzilla.redhat.com/show_bug.cgi?id=1380419

https://bugzilla.redhat.com/show_bug.cgi?id=1380605

https://bugzilla.redhat.com/show_bug.cgi?id=1380619

https://bugzilla.redhat.com/show_bug.cgi?id=1380638

https://bugzilla.redhat.com/show_bug.cgi?id=1380655

https://bugzilla.redhat.com/show_bug.cgi?id=1380710

https://bugzilla.redhat.com/show_bug.cgi?id=1380742

https://bugzilla.redhat.com/show_bug.cgi?id=1381140

https://bugzilla.redhat.com/show_bug.cgi?id=1381353

https://bugzilla.redhat.com/show_bug.cgi?id=1381452

https://bugzilla.redhat.com/show_bug.cgi?id=1381822

https://bugzilla.redhat.com/show_bug.cgi?id=1381831

https://bugzilla.redhat.com/show_bug.cgi?id=1381968

https://bugzilla.redhat.com/show_bug.cgi?id=1382065

https://bugzilla.redhat.com/show_bug.cgi?id=1382277

https://bugzilla.redhat.com/show_bug.cgi?id=1382345

https://bugzilla.redhat.com/show_bug.cgi?id=1384070

https://bugzilla.redhat.com/show_bug.cgi?id=1384311

https://bugzilla.redhat.com/show_bug.cgi?id=1384316

https://bugzilla.redhat.com/show_bug.cgi?id=1384459

https://bugzilla.redhat.com/show_bug.cgi?id=1384460

https://bugzilla.redhat.com/show_bug.cgi?id=1384481

https://bugzilla.redhat.com/show_bug.cgi?id=1384865

https://bugzilla.redhat.com/show_bug.cgi?id=1384993

https://bugzilla.redhat.com/show_bug.cgi?id=1385468

https://bugzilla.redhat.com/show_bug.cgi?id=1385474

https://bugzilla.redhat.com/show_bug.cgi?id=1385525

https://bugzilla.redhat.com/show_bug.cgi?id=1385561

https://bugzilla.redhat.com/show_bug.cgi?id=1385605

https://bugzilla.redhat.com/show_bug.cgi?id=1385606

https://bugzilla.redhat.com/show_bug.cgi?id=1386127

https://bugzilla.redhat.com/show_bug.cgi?id=1386172

https://bugzilla.redhat.com/show_bug.cgi?id=1386177

https://bugzilla.redhat.com/show_bug.cgi?id=1386185

https://bugzilla.redhat.com/show_bug.cgi?id=1386280

https://bugzilla.redhat.com/show_bug.cgi?id=1386366

https://bugzilla.redhat.com/show_bug.cgi?id=1386472

https://bugzilla.redhat.com/show_bug.cgi?id=1386477

https://bugzilla.redhat.com/show_bug.cgi?id=1386538

https://bugzilla.redhat.com/show_bug.cgi?id=1387152

https://bugzilla.redhat.com/show_bug.cgi?id=1387204

https://bugzilla.redhat.com/show_bug.cgi?id=1387205

https://bugzilla.redhat.com/show_bug.cgi?id=1387501

https://bugzilla.redhat.com/show_bug.cgi?id=1387544

https://bugzilla.redhat.com/show_bug.cgi?id=1387558

https://bugzilla.redhat.com/show_bug.cgi?id=1387563

https://bugzilla.redhat.com/show_bug.cgi?id=1388464

https://bugzilla.redhat.com/show_bug.cgi?id=1388560

https://bugzilla.redhat.com/show_bug.cgi?id=1388711

https://bugzilla.redhat.com/show_bug.cgi?id=1388734

https://bugzilla.redhat.com/show_bug.cgi?id=1388755

https://bugzilla.redhat.com/show_bug.cgi?id=1389168

https://bugzilla.redhat.com/show_bug.cgi?id=1392899

https://bugzilla.redhat.com/show_bug.cgi?id=1392906

https://bugzilla.redhat.com/show_bug.cgi?id=1393316

https://bugzilla.redhat.com/show_bug.cgi?id=1393526

https://bugzilla.redhat.com/show_bug.cgi?id=1393694

https://bugzilla.redhat.com/show_bug.cgi?id=1393709

https://bugzilla.redhat.com/show_bug.cgi?id=1393758

https://bugzilla.redhat.com/show_bug.cgi?id=1394219

https://bugzilla.redhat.com/show_bug.cgi?id=1394752

https://bugzilla.redhat.com/show_bug.cgi?id=1395539

https://bugzilla.redhat.com/show_bug.cgi?id=1395541

https://bugzilla.redhat.com/show_bug.cgi?id=1395574

https://bugzilla.redhat.com/show_bug.cgi?id=1395603

https://bugzilla.redhat.com/show_bug.cgi?id=1395613

https://bugzilla.redhat.com/show_bug.cgi?id=1396166

https://bugzilla.redhat.com/show_bug.cgi?id=1396361

https://bugzilla.redhat.com/show_bug.cgi?id=1396449

https://bugzilla.redhat.com/show_bug.cgi?id=1397257

https://bugzilla.redhat.com/show_bug.cgi?id=1397267

https://bugzilla.redhat.com/show_bug.cgi?id=1397286

https://bugzilla.redhat.com/show_bug.cgi?id=1397364

https://bugzilla.redhat.com/show_bug.cgi?id=1397430

https://bugzilla.redhat.com/show_bug.cgi?id=1397450

https://bugzilla.redhat.com/show_bug.cgi?id=1397681

https://bugzilla.redhat.com/show_bug.cgi?id=1397846

https://bugzilla.redhat.com/show_bug.cgi?id=1398188

https://bugzilla.redhat.com/show_bug.cgi?id=1398257

https://bugzilla.redhat.com/show_bug.cgi?id=1398261

https://bugzilla.redhat.com/show_bug.cgi?id=1398311

https://bugzilla.redhat.com/show_bug.cgi?id=1398315

https://bugzilla.redhat.com/show_bug.cgi?id=1398331

https://bugzilla.redhat.com/show_bug.cgi?id=1398798

https://bugzilla.redhat.com/show_bug.cgi?id=1399100

https://bugzilla.redhat.com/show_bug.cgi?id=1399105

https://bugzilla.redhat.com/show_bug.cgi?id=1399476

https://bugzilla.redhat.com/show_bug.cgi?id=1399598

https://bugzilla.redhat.com/show_bug.cgi?id=1399698

https://bugzilla.redhat.com/show_bug.cgi?id=1399753

https://bugzilla.redhat.com/show_bug.cgi?id=1399757

https://bugzilla.redhat.com/show_bug.cgi?id=1400037

https://bugzilla.redhat.com/show_bug.cgi?id=1400057

https://bugzilla.redhat.com/show_bug.cgi?id=1400068

https://bugzilla.redhat.com/show_bug.cgi?id=1400093

https://bugzilla.redhat.com/show_bug.cgi?id=1400395

https://bugzilla.redhat.com/show_bug.cgi?id=1400599

https://bugzilla.redhat.com/show_bug.cgi?id=1401380

https://bugzilla.redhat.com/show_bug.cgi?id=1401806

https://bugzilla.redhat.com/show_bug.cgi?id=1401814

https://bugzilla.redhat.com/show_bug.cgi?id=1401817

https://bugzilla.redhat.com/show_bug.cgi?id=1401869

https://bugzilla.redhat.com/show_bug.cgi?id=1402360

https://bugzilla.redhat.com/show_bug.cgi?id=1402683

https://bugzilla.redhat.com/show_bug.cgi?id=1402774

https://bugzilla.redhat.com/show_bug.cgi?id=1403120

https://bugzilla.redhat.com/show_bug.cgi?id=1403672

https://bugzilla.redhat.com/show_bug.cgi?id=1403770

https://bugzilla.redhat.com/show_bug.cgi?id=1403840

https://bugzilla.redhat.com/show_bug.cgi?id=1404110

https://bugzilla.redhat.com/show_bug.cgi?id=1404541

https://bugzilla.redhat.com/show_bug.cgi?id=1404569

https://bugzilla.redhat.com/show_bug.cgi?id=1404633

https://bugzilla.redhat.com/show_bug.cgi?id=1404982

https://bugzilla.redhat.com/show_bug.cgi?id=1404989

https://bugzilla.redhat.com/show_bug.cgi?id=1404996

https://bugzilla.redhat.com/show_bug.cgi?id=1405000

https://bugzilla.redhat.com/show_bug.cgi?id=1405299

https://bugzilla.redhat.com/show_bug.cgi?id=1405302

https://bugzilla.redhat.com/show_bug.cgi?id=1406025

https://bugzilla.redhat.com/show_bug.cgi?id=1406322

https://bugzilla.redhat.com/show_bug.cgi?id=1406401

https://bugzilla.redhat.com/show_bug.cgi?id=1406723

https://bugzilla.redhat.com/show_bug.cgi?id=1408112

https://bugzilla.redhat.com/show_bug.cgi?id=1408413

https://bugzilla.redhat.com/show_bug.cgi?id=1408426

https://bugzilla.redhat.com/show_bug.cgi?id=1408576

https://bugzilla.redhat.com/show_bug.cgi?id=1408639

https://bugzilla.redhat.com/show_bug.cgi?id=1408641

https://bugzilla.redhat.com/show_bug.cgi?id=1408655

https://bugzilla.redhat.com/show_bug.cgi?id=1408705

https://bugzilla.redhat.com/show_bug.cgi?id=1408836

https://bugzilla.redhat.com/show_bug.cgi?id=1409135

https://bugzilla.redhat.com/show_bug.cgi?id=1409472

https://bugzilla.redhat.com/show_bug.cgi?id=1409563

https://bugzilla.redhat.com/show_bug.cgi?id=1409782

https://bugzilla.redhat.com/show_bug.cgi?id=1409808

https://bugzilla.redhat.com/show_bug.cgi?id=1410025

https://bugzilla.redhat.com/show_bug.cgi?id=1410406

https://bugzilla.redhat.com/show_bug.cgi?id=1411270

https://bugzilla.redhat.com/show_bug.cgi?id=1411329

https://bugzilla.redhat.com/show_bug.cgi?id=1411617

https://bugzilla.redhat.com/show_bug.cgi?id=1412554

https://bugzilla.redhat.com/show_bug.cgi?id=1412955

https://bugzilla.redhat.com/show_bug.cgi?id=1413351

https://bugzilla.redhat.com/show_bug.cgi?id=1413513

https://bugzilla.redhat.com/show_bug.cgi?id=1414247

https://bugzilla.redhat.com/show_bug.cgi?id=1414663

https://bugzilla.redhat.com/show_bug.cgi?id=1415101

https://bugzilla.redhat.com/show_bug.cgi?id=1415583

https://bugzilla.redhat.com/show_bug.cgi?id=1417177

https://bugzilla.redhat.com/show_bug.cgi?id=1417955

https://bugzilla.redhat.com/show_bug.cgi?id=1418011

https://bugzilla.redhat.com/show_bug.cgi?id=1418603

https://bugzilla.redhat.com/show_bug.cgi?id=1418901

https://bugzilla.redhat.com/show_bug.cgi?id=1419859

https://bugzilla.redhat.com/show_bug.cgi?id=1420324

https://bugzilla.redhat.com/show_bug.cgi?id=1420635

https://bugzilla.redhat.com/show_bug.cgi?id=1422431

https://bugzilla.redhat.com/show_bug.cgi?id=1422576

https://bugzilla.redhat.com/show_bug.cgi?id=1425740

https://bugzilla.redhat.com/show_bug.cgi?id=1426324

https://bugzilla.redhat.com/show_bug.cgi?id=1426559

https://bugzilla.redhat.com/show_bug.cgi?id=1427783

https://bugzilla.redhat.com/show_bug.cgi?id=1389422

https://bugzilla.redhat.com/show_bug.cgi?id=1389661

https://bugzilla.redhat.com/show_bug.cgi?id=1390843

https://bugzilla.redhat.com/show_bug.cgi?id=1391072

https://bugzilla.redhat.com/show_bug.cgi?id=1391093

https://bugzilla.redhat.com/show_bug.cgi?id=1391808

https://bugzilla.redhat.com/show_bug.cgi?id=1392299

https://bugzilla.redhat.com/show_bug.cgi?id=1392761

https://bugzilla.redhat.com/show_bug.cgi?id=1392837

https://bugzilla.redhat.com/show_bug.cgi?id=1392895

Plugin Details

Severity: High

ID: 97929

File Name: redhat-RHSA-2017-0486.nasl

Version: 3.14

Type: local

Agent: unix

Published: 3/24/2017

Updated: 3/20/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2015-1795

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:glusterfs-cli, p-cpe:/a:redhat:enterprise_linux:glusterfs-ganesha, p-cpe:/a:redhat:enterprise_linux:glusterfs-devel, p-cpe:/a:redhat:enterprise_linux:vdsm-infra, p-cpe:/a:redhat:enterprise_linux:vdsm-tests, p-cpe:/a:redhat:enterprise_linux:glusterfs-api, p-cpe:/a:redhat:enterprise_linux:glusterfs, p-cpe:/a:redhat:enterprise_linux:glusterfs-client-xlators, p-cpe:/a:redhat:enterprise_linux:vdsm-python, p-cpe:/a:redhat:enterprise_linux:vdsm-hook-openstacknet, p-cpe:/a:redhat:enterprise_linux:vdsm-jsonrpc, p-cpe:/a:redhat:enterprise_linux:glusterfs-rdma, p-cpe:/a:redhat:enterprise_linux:glusterfs-server, p-cpe:/a:redhat:enterprise_linux:glusterfs-events, p-cpe:/a:redhat:enterprise_linux:vdsm-hook-qemucmdline, p-cpe:/a:redhat:enterprise_linux:vdsm-hook-ethtool-options, p-cpe:/a:redhat:enterprise_linux:vdsm-xmlrpc, p-cpe:/a:redhat:enterprise_linux:glusterfs-api-devel, p-cpe:/a:redhat:enterprise_linux:glusterfs-fuse, p-cpe:/a:redhat:enterprise_linux:vdsm-gluster, p-cpe:/a:redhat:enterprise_linux:redhat-storage-server, p-cpe:/a:redhat:enterprise_linux:glusterfs-geo-replication, p-cpe:/a:redhat:enterprise_linux:vdsm-hook-faqemu, p-cpe:/a:redhat:enterprise_linux:vdsm, p-cpe:/a:redhat:enterprise_linux:vdsm-debug-plugin, p-cpe:/a:redhat:enterprise_linux:vdsm-yajsonrpc, p-cpe:/a:redhat:enterprise_linux:python-gluster, cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:glusterfs-libs, p-cpe:/a:redhat:enterprise_linux:vdsm-cli

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 3/23/2017

Vulnerability Publication Date: 6/27/2017

Reference Information

CVE: CVE-2015-1795

CWE: 377

RHSA: 2017:0486