Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.2095 OpenShift Container Platform 4.3.25 security updates 18 June 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: OpenShift Container Platform 4.3.25 Publisher: Red Hat Operating System: Red Hat Enterprise Linux Server 7 Red Hat Enterprise Linux Server 8 Red Hat Impact/Access: Root Compromise -- Existing Account Denial of Service -- Remote/Unauthenticated Provide Misleading Information -- Existing Account Access Confidential Data -- Existing Account Reduced Security -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2020-10749 CVE-2020-8617 CVE-2020-8616 CVE-2020-8555 CVE-2020-1750 CVE-2020-1706 Reference: ESB-2020.1975 ESB-2020.1951 ESB-2020.1946 ESB-2020.1582 Original Bulletin: https://access.redhat.com/errata/RHSA-2020:2439 https://access.redhat.com/errata/RHSA-2020:2440 https://access.redhat.com/errata/RHSA-2020:2441 https://access.redhat.com/errata/RHSA-2020:2442 https://access.redhat.com/errata/RHSA-2020:2443 Comment: This bulletin contains five (5) Red Hat security advisories. - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.3.25 security update Advisory ID: RHSA-2020:2439-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:2439 Issue date: 2020-06-17 CVE Names: CVE-2020-1750 CVE-2020-8616 CVE-2020-8617 ===================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.3.25 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * machine-config-operator-container: A flaw in the machine-config-operator caused an OpenShift node to become unresponsive when a container consumes a large amount of memory (CVE-2020-1750) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for release 4.3.25, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel ease-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster - - -cli.html. 4. Bugs fixed (https://bugzilla.redhat.com/): 1808130 - CVE-2020-1750 machine-config-operator-container: mmap stressor makes the cluster unresponsive 5. References: https://access.redhat.com/security/cve/CVE-2020-1750 https://access.redhat.com/security/cve/CVE-2020-8616 https://access.redhat.com/security/cve/CVE-2020-8617 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXup64NzjgjWX9erEAQhLzBAAjUGcukEPjWhsN/f/QWqHD2AdY4TrBeZB TxPobbVcChTvA0mW0hV2dQj7HUS5DwIBip/7YfXD5pi7D5cLmAGx0/OoEQXBVOTb VnDXM02RFKKay7DDaAIDYy1s2r3R43cEXUDXjNfbjNpXW5foL8Qqr1eW5Gaze8aT Iymw+ygsu3E/L55Sz6kBfi3owaTKxVKaYUp7Wjn1rJ+imXzztC/FCV7oWM5yVtYE FE0zgXBOEdMs7dZzTgR9rcrB58C8+8bTbcFPiy0Zou46Vz/tD+Zu7PtOszKU2anH MEHguXPDlN0VBLLya+rMX1Shk+zK2ZwanOYa9/jFK3GuLYtgpwxgKxIZVXiRZCQX KzygWW5ZLcbzI+KPZqqDy3e65QFayUS3hUuMNnVIWUnznOQCGEgQVA+3X1rwnARc XOS3YyYfSs1va3ZTHajWtaDdZujdXjLjeknwJIv6dwX+PnKN47P2+YX6viyNJWdU LDB4ty4D7PyA1EcZduORgvQBAquvysIsBrNzQkNX+D/15g8l1t22M4F4CiGRi+Uc qnD5HThxUHivkjGsECpETnT0PTFXrM3EbrxWUZG4IatWex5oBeFd+Off+/ljQ+Yq Uk/Z/J+Ozk2OFZF5xmyRZ4B8IT2ZOWm/Zl49KhO7gKCu4MLLpQUZG0/IXMH5p1Pe 1F/l77ClqDc= =2wX7 - -----END PGP SIGNATURE----- - -------------------------------------------------------------------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.3.25 openshift security update Advisory ID: RHSA-2020:2440-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:2440 Issue date: 2020-06-17 CVE Names: CVE-2020-8555 ===================================================================== 1. Summary: An update for openshift is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenShift Container Platform 4.3 - ppc64le, s390x, x86_64 3. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * kubernetes: A server side request forgery (SSRF) in the kube-controller-manager allows certain authorized users to leak up to 500 bytes of arbitrary information from the master's host network (CVE-2020-8555) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for release 4.3.25, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel ease-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster - - -cli.html. 5. Bugs fixed (https://bugzilla.redhat.com/): 1821583 - CVE-2020-8555 kubernetes: Server side request forgery (SSRF) in kube-controller-manager allows users to leak secret information 6. Package List: Red Hat OpenShift Container Platform 4.3: Source: openshift-4.3.25-202006060952.git.1.96c30f6.el7.src.rpm ppc64le: openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el7.ppc64le.rpm s390x: openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el7.s390x.rpm x86_64: openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el7.x86_64.rpm Red Hat OpenShift Container Platform 4.3: Source: openshift-4.3.25-202006060952.git.1.96c30f6.el8.src.rpm ppc64le: openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el8.ppc64le.rpm s390x: openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el8.s390x.rpm x86_64: openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-8555 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXupzJNzjgjWX9erEAQjjEg//c0hMjjarpUl4l+hzx6zzvBBm4YtINNqY GzBujkNdM/+sesJKC7VSh+XqemtYoW6FFwTlRDE3gQ0t0EyRc6Q6Wf00cgoI7bkz mrhwtJYYupOVfIm91G94cZCNmndPxVZxzS/kht1fgSSMsO37Uw/6M/js0BdzAUyc PCFfyxoneSvWkmivJvip+0p4ta6g95zVYXrnGGBrjefK75aG2kypY7zG1J6L5pcw n6YMzpCIOTr+bgM9DQUg+WWfq/hh/AQAHCv2Zl4HWNta5K8yyMat50KrWQigXAeh nrDDN3BuKMW9uUSQQ3FnoqAPwzLLNtPQ6rpNEXdXUFZzZtnO60CR3iGCvoUODOdz wuh5XYXUiW3WxntQ1mqsoPyjLnAxr8pqqT+coZRHhStyiHYFLlJrofqMwuYo46k1 HTxCpPW5gvZJC1aibmbiyPz1hGbrZcsDHyoVpCeZNmzXKu0L3+TAZQKYDfSnU3Le Z2q/f+lnSYa4VEn3LtHOC0iCfGmkBa6Yi/iTKMr4Cb8ZU+P6mf7m4dCGdBsbEC3D CemE/Y6NoaKUn1GvTkHUNJ1BTsxixNO338MMbIhwBObOnvnM+F7I92Xrs6n4Ne4y ZisOg448KjFk9XGc9xcs6BSznojR6phpCdP7gYLAKP1bVzXIT6S712yMPfsTnRe9 NGbRs1fL0Ac= =87is - -----END PGP SIGNATURE----- - -------------------------------------------------------------------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.3.25 openshift-enterprise-hyperkube-container security update Advisory ID: RHSA-2020:2441-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:2441 Issue date: 2020-06-17 CVE Names: CVE-2020-8555 CVE-2020-8616 CVE-2020-8617 ===================================================================== 1. Summary: An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * kubernetes: A server side request forgery (SSRF) in the kube-controller-manager allows certain authorized users to leak up to 500 bytes of arbitrary information from the master's host network (CVE-2020-8555) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for release 4.3.25, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel ease-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster - - -cli.html. 4. Bugs fixed (https://bugzilla.redhat.com/): 1821583 - CVE-2020-8555 kubernetes: Server side request forgery (SSRF) in kube-controller-manager allows users to leak secret information 5. References: https://access.redhat.com/security/cve/CVE-2020-8555 https://access.redhat.com/security/cve/CVE-2020-8616 https://access.redhat.com/security/cve/CVE-2020-8617 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXup7E9zjgjWX9erEAQhz3w/+MghcFXeMqzS16vChsj7ucxG8RIBclbNj wfdRpZlH2U8eniNjAObe4iE/gZGC/Rb4mVYHRmaNYms+dPjRVG3q95IEtPIQ1+oA fZTTa+l3XaElKnXhc3of9qdmkgz1dh9CdHeRa5zTFWfBliM4FpHuzyFeOjB0IVTM c18kfQinMUCUIHL7z2Uis6vcfbJdyAW1+k/t+0Q0p2HbNL/bBcp8c9ca0w1y5blm +bu5J+J7tQH6TxbVWIqAFjBnASHfrsgjXcYkBomu08qILo0PhhGbWs3s8CJ9nL/I ByuVPUIoeCSi3wSc9GuxUZ3GF3Tf96GX1NQC0xJKe+qDzpUVgsyCiVC2herBRAX2 qACWpSns6ByyVpE0EbQtuF4tiealdtVBkLiEx8w3VrbYgqFFuiOMe7yFmm19YJ6Q 35YychyuQiMdfbOeoh+8gh9F8aGgebLR+iNGBKMVIQ93ap34mIVCY+YRQM2g2A8P w+EVV354DMW1e4+enaJYT62BPO/4CC1ehdnP7gE5qnBBg0ZTPhuGwYLFVWOGbl+p g7pBIrtbw/hhNkgiNZz9RXjWc1q9hAVqxo3XnPFp/4Fct2oRYPVNsAUncMbnHgPC I7rP46M7RwgD7MOAow6g8DLF2/kQJ4aLIh/Tvp+MoMggKTE+mjnR2AjOzUB4V2Oc P3hLuEDorsc= =WykC - -----END PGP SIGNATURE----- - -------------------------------------------------------------------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.3.25 openshift-enterprise-apb-tools-container security update Advisory ID: RHSA-2020:2442-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:2442 Issue date: 2020-06-17 CVE Names: CVE-2020-1706 ===================================================================== 1. Summary: An update for openshift-enterprise-apb-tools-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * openshift/apb-tools: A container privilege escalation vulnerability allowed any user within the container to escalate to root (CVE-2020-1706) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for release 4.3.25, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel ease-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster - - -cli.html. 4. Bugs fixed (https://bugzilla.redhat.com/): 1793302 - CVE-2020-1706 openshift/apb-tools: /etc/passwd is given incorrect privileges 5. References: https://access.redhat.com/security/cve/CVE-2020-1706 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXup6+dzjgjWX9erEAQhTkw//U+nlH/agc4ZM4x/OUkwsIfjbX2aiQg8b SW6Zq4kRoqODsp/7bC4Lbd+MpTEvv75fZeOL0XLCL5koVMFf3jQMfCiXxf6odEpG iRbJCIlyc02s6vvqRgo3iC6DukveVgayRl7bKdoftVbXNRXbzJfsDVoAHxSlLWOj Uv16gaGEF7O6VOiUDNTKejRLDLgPFgITniCuMEOFUveWejP3OByCwModwv5s9fk/ G85k3CnGrx8ROdQnDxo+OYLs9CFom3DdP7TCBE9qgNf4EJBAeAive1A/kovCqOIx AdnLyAs+9YEf3p2IBvq0W3N29JXNTMcusjwQ/GgCnAAmVnw9/ilPTqiZlycVpf8x OwDVKPqlUJxkDIyB9JhdEINUWC5KokC5Do3bqSZnyeOmlQPyEZ4JVTZhXRlSXJnx 3QE8BCiUDMOiz5yABKS8hRiuLiDYQLYSolQND824nQmVeM1n+ZTxW2uq/ACmxhKx S7GPk35SB0tFF/GuNzQ4kvqTkKEbBZDGAhhod7ujxfQ7Z5WmusDm7O33Vij4IrZO W5NmCxHvd1bpIOINjBvtiIQmSnCxK7PIENCJVHuZtgxyW5kLAiD0KEVJq84hzZyQ QD6nOc58CitvGIo43Erlv877PYXB86dd1lFW1f0pn3LliV08LhbtT6UzDP0uzHGm m2l2GEKNg8w= =juiT - -----END PGP SIGNATURE----- - -------------------------------------------------------------------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.3.25 containernetworking-plugins security update Advisory ID: RHSA-2020:2443-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:2443 Issue date: 2020-06-17 CVE Names: CVE-2020-10749 ===================================================================== 1. Summary: An update for containernetworking-plugins is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenShift Container Platform 4.3 - ppc64le, s390x, x86_64 3. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * containernetworking/plugins: A vulnerability in IPv4 networking implementations allowed malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks by redirecting traffic to the malicious container with â\x{128}\x{156}rogueâ\x{128}\x{157} IPv6 router advertisements. (CVE-2020-10749) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for release 4.3.25, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel ease-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster - - -cli.html. 5. Bugs fixed (https://bugzilla.redhat.com/): 1833220 - CVE-2020-10749 containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters 6. Package List: Red Hat OpenShift Container Platform 4.3: Source: containernetworking-plugins-0.8.6-1.rhaos4.3.el7.src.rpm ppc64le: containernetworking-plugins-0.8.6-1.rhaos4.3.el7.ppc64le.rpm containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el7.ppc64le.rpm s390x: containernetworking-plugins-0.8.6-1.rhaos4.3.el7.s390x.rpm containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el7.s390x.rpm x86_64: containernetworking-plugins-0.8.6-1.rhaos4.3.el7.x86_64.rpm containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el7.x86_64.rpm Red Hat OpenShift Container Platform 4.3: Source: containernetworking-plugins-0.8.6-1.rhaos4.3.el8.src.rpm ppc64le: containernetworking-plugins-0.8.6-1.rhaos4.3.el8.ppc64le.rpm containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el8.ppc64le.rpm containernetworking-plugins-debugsource-0.8.6-1.rhaos4.3.el8.ppc64le.rpm s390x: containernetworking-plugins-0.8.6-1.rhaos4.3.el8.s390x.rpm containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el8.s390x.rpm containernetworking-plugins-debugsource-0.8.6-1.rhaos4.3.el8.s390x.rpm x86_64: containernetworking-plugins-0.8.6-1.rhaos4.3.el8.x86_64.rpm containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el8.x86_64.rpm containernetworking-plugins-debugsource-0.8.6-1.rhaos4.3.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-10749 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXupzCdzjgjWX9erEAQgemQ//bdhSByTD4ridz2qEAt46DsKkqprKT5dv ZfVYx1ng8MbwFHUK/RsVpbBfKO1YWfTGMmegK1oC5NSr9t2dqVkghQPFVtUjNAMc ZtKIN92WOSOQYZJJxBIrTDISQRmsCoh5vcbK0jwNPpubgr6k4+f+fhIeip6zwEl/ 6CVta0gQvtYZyKENZ0tGqQ8Gtty+ovxg/5y4TgmpuWyO8aF1hNAMH/icUawk/F0+ DcLmhlYqrYG+LgLJXLS5Dkd3vEvxLSAWCGV0CTQmvXbO1nYBCuSuqYD4/55CZwi6 E3d4mXmEwFTHiIFJVDr7yhK0z0wMKi0bewdELnrFTpuaAzdHrsK2+WAfTTQuMswT W6QRLV6ciwLikdMBBMB3yiFe5aCmcDb5xjOT/JbsSgFbATprSR6I3A7086DHsVRl 4NbefKjaKfM1FZTzXkjVJbUZglUu/aE1xnfk/lXm7SExpWLm5XphEkremDxkrZiA ZobKBv3UIwVItsUhTvPxorWs1ZQY70u8BtNit/l6XeiE2C0gN0XRCZj8HLdVbHDL bmrJeyZUdjX6VQ7mPJs3p0eJzAm+CIQiw5sfM0rqxvFzzMeUfQtyg8T0rlbHlxSy Dpo0XtGY/Aa6pMkYEA2Oe6yn+O7mOy2prSe1Qzt4y2oZRZNZ0lj8tuc5OSSn/kud dPzHcNBbvW0= =9tKD - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXuq/guNLKJtyKPYoAQjrhBAAhjpzHFDvRLnQmA3UHortr6+oUxxLEUKq Hc7XSSi2RcSG2+owlhcFLoegnlUcYqVjh/ibwxLDRiydyTHKUcEhet660XL9n+N2 ZqbomWUeiFo96rD6vTraPApGhsXu6w3bb140Nc/pgjrXHwbYKRUXEjRb9MPgbE9o HLEOzGmysXizmb36Q0XrSzPY3gK9Z7uMrPOMZzaJJBp/I2B2y1B6D1ORibWosI2i 3id28nKgBfH5L9JFvS1Lf7AvJfgyEUK3SSTFu4ucKqUui/piDBDvmGZITGXuffXw Vd0ZW76B1gGzLmdtUCNQO99SEauY7BNOCpcmaX9HObnHPbUTn/EL8ALBVB1htMfr hvjnpDKLAe5pNzXLwvwMjQLDpqm6PZqorRtdnrzrFXe9lPpxeQPKUYTYOm47Y30I XOaszTpMt4rtoPyr3j9CwNU1gwZphbaiFRbfk+JUCG1t+NO9N3C07rRx4Y++grmW bExOjl4SdeSZN3eBuMFrN45zixQrcn/jbgGv4n+v3DkoMV99JGq9vfaQXCYAmvAH eXiMGiAsH5avW/nbmhPVC0Y003Nenr5g7r4DcFBTP5PiRddDGOy4MVOhssSuFPrB CNUskA5o+I0KIsJAx/uhPSQqoqkDN7HzCMgkGng7b4gCbIxoQ/k2nJRy1YQ8SiTk SmisLo7akqM= =QJx5 -----END PGP SIGNATURE-----