-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.2095
           OpenShift Container Platform 4.3.25 security updates
                               18 June 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           OpenShift Container Platform 4.3.25
Publisher:         Red Hat
Operating System:  Red Hat Enterprise Linux Server 7
                   Red Hat Enterprise Linux Server 8
                   Red Hat
Impact/Access:     Root Compromise                -- Existing Account      
                   Denial of Service              -- Remote/Unauthenticated
                   Provide Misleading Information -- Existing Account      
                   Access Confidential Data       -- Existing Account      
                   Reduced Security               -- Existing Account      
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-10749 CVE-2020-8617 CVE-2020-8616
                   CVE-2020-8555 CVE-2020-1750 CVE-2020-1706

Reference:         ESB-2020.1975
                   ESB-2020.1951
                   ESB-2020.1946
                   ESB-2020.1582

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2020:2439
   https://access.redhat.com/errata/RHSA-2020:2440
   https://access.redhat.com/errata/RHSA-2020:2441
   https://access.redhat.com/errata/RHSA-2020:2442
   https://access.redhat.com/errata/RHSA-2020:2443

Comment: This bulletin contains five (5) Red Hat security advisories.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: OpenShift Container Platform 4.3.25 security update
Advisory ID:       RHSA-2020:2439-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2439
Issue date:        2020-06-17
CVE Names:         CVE-2020-1750 CVE-2020-8616 CVE-2020-8617 
=====================================================================

1. Summary:

Red Hat OpenShift Container Platform release 4.3.25 is now available with
updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
Security Fix(es):

* machine-config-operator-container: A flaw in the machine-config-operator
caused an OpenShift node to become unresponsive when a container consumes a
large amount of memory (CVE-2020-1750)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s)
listed in the References section.

3. Solution:

For OpenShift Container Platform 4.3 see the following documentation, which
will be updated shortly for release 4.3.25, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel
ease-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.3/updating/updating-cluster
- - -cli.html.

4. Bugs fixed (https://bugzilla.redhat.com/):

1808130 - CVE-2020-1750 machine-config-operator-container: mmap stressor makes 
the cluster unresponsive

5. References:

https://access.redhat.com/security/cve/CVE-2020-1750
https://access.redhat.com/security/cve/CVE-2020-8616
https://access.redhat.com/security/cve/CVE-2020-8617
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXup64NzjgjWX9erEAQhLzBAAjUGcukEPjWhsN/f/QWqHD2AdY4TrBeZB
TxPobbVcChTvA0mW0hV2dQj7HUS5DwIBip/7YfXD5pi7D5cLmAGx0/OoEQXBVOTb
VnDXM02RFKKay7DDaAIDYy1s2r3R43cEXUDXjNfbjNpXW5foL8Qqr1eW5Gaze8aT
Iymw+ygsu3E/L55Sz6kBfi3owaTKxVKaYUp7Wjn1rJ+imXzztC/FCV7oWM5yVtYE
FE0zgXBOEdMs7dZzTgR9rcrB58C8+8bTbcFPiy0Zou46Vz/tD+Zu7PtOszKU2anH
MEHguXPDlN0VBLLya+rMX1Shk+zK2ZwanOYa9/jFK3GuLYtgpwxgKxIZVXiRZCQX
KzygWW5ZLcbzI+KPZqqDy3e65QFayUS3hUuMNnVIWUnznOQCGEgQVA+3X1rwnARc
XOS3YyYfSs1va3ZTHajWtaDdZujdXjLjeknwJIv6dwX+PnKN47P2+YX6viyNJWdU
LDB4ty4D7PyA1EcZduORgvQBAquvysIsBrNzQkNX+D/15g8l1t22M4F4CiGRi+Uc
qnD5HThxUHivkjGsECpETnT0PTFXrM3EbrxWUZG4IatWex5oBeFd+Off+/ljQ+Yq
Uk/Z/J+Ozk2OFZF5xmyRZ4B8IT2ZOWm/Zl49KhO7gKCu4MLLpQUZG0/IXMH5p1Pe
1F/l77ClqDc=
=2wX7
- -----END PGP SIGNATURE-----


- --------------------------------------------------------------------------------


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: OpenShift Container Platform 4.3.25 openshift security update
Advisory ID:       RHSA-2020:2440-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2440
Issue date:        2020-06-17
CVE Names:         CVE-2020-8555 
=====================================================================

1. Summary:

An update for openshift is now available for Red Hat OpenShift Container
Platform 4.3.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat OpenShift Container Platform 4.3 - ppc64le, s390x, x86_64

3. Description:

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

Security Fix(es):

* kubernetes: A server side request forgery (SSRF) in the
kube-controller-manager allows certain authorized users to leak up to 500
bytes of arbitrary information from the master's host network
(CVE-2020-8555)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For OpenShift Container Platform 4.3 see the following documentation, which
will be updated shortly for release 4.3.25, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel
ease-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.3/updating/updating-cluster
- - -cli.html.

5. Bugs fixed (https://bugzilla.redhat.com/):

1821583 - CVE-2020-8555 kubernetes: Server side request forgery (SSRF) in 
kube-controller-manager allows users to leak secret information

6. Package List:

Red Hat OpenShift Container Platform 4.3:

Source:
openshift-4.3.25-202006060952.git.1.96c30f6.el7.src.rpm

ppc64le:
openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el7.ppc64le.rpm

s390x:
openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el7.s390x.rpm

x86_64:
openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el7.x86_64.rpm

Red Hat OpenShift Container Platform 4.3:

Source:
openshift-4.3.25-202006060952.git.1.96c30f6.el8.src.rpm

ppc64le:
openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el8.ppc64le.rpm

s390x:
openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el8.s390x.rpm

x86_64:
openshift-hyperkube-4.3.25-202006060952.git.1.96c30f6.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-8555
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXupzJNzjgjWX9erEAQjjEg//c0hMjjarpUl4l+hzx6zzvBBm4YtINNqY
GzBujkNdM/+sesJKC7VSh+XqemtYoW6FFwTlRDE3gQ0t0EyRc6Q6Wf00cgoI7bkz
mrhwtJYYupOVfIm91G94cZCNmndPxVZxzS/kht1fgSSMsO37Uw/6M/js0BdzAUyc
PCFfyxoneSvWkmivJvip+0p4ta6g95zVYXrnGGBrjefK75aG2kypY7zG1J6L5pcw
n6YMzpCIOTr+bgM9DQUg+WWfq/hh/AQAHCv2Zl4HWNta5K8yyMat50KrWQigXAeh
nrDDN3BuKMW9uUSQQ3FnoqAPwzLLNtPQ6rpNEXdXUFZzZtnO60CR3iGCvoUODOdz
wuh5XYXUiW3WxntQ1mqsoPyjLnAxr8pqqT+coZRHhStyiHYFLlJrofqMwuYo46k1
HTxCpPW5gvZJC1aibmbiyPz1hGbrZcsDHyoVpCeZNmzXKu0L3+TAZQKYDfSnU3Le
Z2q/f+lnSYa4VEn3LtHOC0iCfGmkBa6Yi/iTKMr4Cb8ZU+P6mf7m4dCGdBsbEC3D
CemE/Y6NoaKUn1GvTkHUNJ1BTsxixNO338MMbIhwBObOnvnM+F7I92Xrs6n4Ne4y
ZisOg448KjFk9XGc9xcs6BSznojR6phpCdP7gYLAKP1bVzXIT6S712yMPfsTnRe9
NGbRs1fL0Ac=
=87is
- -----END PGP SIGNATURE-----


- --------------------------------------------------------------------------------


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: OpenShift Container Platform 4.3.25 openshift-enterprise-hyperkube-container security update
Advisory ID:       RHSA-2020:2441-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2441
Issue date:        2020-06-17
CVE Names:         CVE-2020-8555 CVE-2020-8616 CVE-2020-8617 
=====================================================================

1. Summary:

An update for openshift-enterprise-hyperkube-container is now available for
Red Hat OpenShift Container Platform 4.3.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

Security Fix(es):

* kubernetes: A server side request forgery (SSRF) in the
kube-controller-manager allows certain authorized users to leak up to 500
bytes of arbitrary information from the master's host network
(CVE-2020-8555)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For OpenShift Container Platform 4.3 see the following documentation, which
will be updated shortly for release 4.3.25, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel
ease-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.3/updating/updating-cluster
- - -cli.html.

4. Bugs fixed (https://bugzilla.redhat.com/):

1821583 - CVE-2020-8555 kubernetes: Server side request forgery (SSRF) in kube-controller-manager allows users to leak secret information

5. References:

https://access.redhat.com/security/cve/CVE-2020-8555
https://access.redhat.com/security/cve/CVE-2020-8616
https://access.redhat.com/security/cve/CVE-2020-8617
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXup7E9zjgjWX9erEAQhz3w/+MghcFXeMqzS16vChsj7ucxG8RIBclbNj
wfdRpZlH2U8eniNjAObe4iE/gZGC/Rb4mVYHRmaNYms+dPjRVG3q95IEtPIQ1+oA
fZTTa+l3XaElKnXhc3of9qdmkgz1dh9CdHeRa5zTFWfBliM4FpHuzyFeOjB0IVTM
c18kfQinMUCUIHL7z2Uis6vcfbJdyAW1+k/t+0Q0p2HbNL/bBcp8c9ca0w1y5blm
+bu5J+J7tQH6TxbVWIqAFjBnASHfrsgjXcYkBomu08qILo0PhhGbWs3s8CJ9nL/I
ByuVPUIoeCSi3wSc9GuxUZ3GF3Tf96GX1NQC0xJKe+qDzpUVgsyCiVC2herBRAX2
qACWpSns6ByyVpE0EbQtuF4tiealdtVBkLiEx8w3VrbYgqFFuiOMe7yFmm19YJ6Q
35YychyuQiMdfbOeoh+8gh9F8aGgebLR+iNGBKMVIQ93ap34mIVCY+YRQM2g2A8P
w+EVV354DMW1e4+enaJYT62BPO/4CC1ehdnP7gE5qnBBg0ZTPhuGwYLFVWOGbl+p
g7pBIrtbw/hhNkgiNZz9RXjWc1q9hAVqxo3XnPFp/4Fct2oRYPVNsAUncMbnHgPC
I7rP46M7RwgD7MOAow6g8DLF2/kQJ4aLIh/Tvp+MoMggKTE+mjnR2AjOzUB4V2Oc
P3hLuEDorsc=
=WykC
- -----END PGP SIGNATURE-----


- --------------------------------------------------------------------------------


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: OpenShift Container Platform 4.3.25 openshift-enterprise-apb-tools-container security update
Advisory ID:       RHSA-2020:2442-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2442
Issue date:        2020-06-17
CVE Names:         CVE-2020-1706 
=====================================================================

1. Summary:

An update for openshift-enterprise-apb-tools-container is now available for
Red Hat OpenShift Container Platform 4.3.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

Security Fix(es):

* openshift/apb-tools: A container privilege escalation vulnerability
allowed any user within the container to escalate to root (CVE-2020-1706)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For OpenShift Container Platform 4.3 see the following documentation, which
will be updated shortly for release 4.3.25, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel
ease-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.3/updating/updating-cluster
- - -cli.html.

4. Bugs fixed (https://bugzilla.redhat.com/):

1793302 - CVE-2020-1706 openshift/apb-tools: /etc/passwd is given incorrect privileges

5. References:

https://access.redhat.com/security/cve/CVE-2020-1706
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXup6+dzjgjWX9erEAQhTkw//U+nlH/agc4ZM4x/OUkwsIfjbX2aiQg8b
SW6Zq4kRoqODsp/7bC4Lbd+MpTEvv75fZeOL0XLCL5koVMFf3jQMfCiXxf6odEpG
iRbJCIlyc02s6vvqRgo3iC6DukveVgayRl7bKdoftVbXNRXbzJfsDVoAHxSlLWOj
Uv16gaGEF7O6VOiUDNTKejRLDLgPFgITniCuMEOFUveWejP3OByCwModwv5s9fk/
G85k3CnGrx8ROdQnDxo+OYLs9CFom3DdP7TCBE9qgNf4EJBAeAive1A/kovCqOIx
AdnLyAs+9YEf3p2IBvq0W3N29JXNTMcusjwQ/GgCnAAmVnw9/ilPTqiZlycVpf8x
OwDVKPqlUJxkDIyB9JhdEINUWC5KokC5Do3bqSZnyeOmlQPyEZ4JVTZhXRlSXJnx
3QE8BCiUDMOiz5yABKS8hRiuLiDYQLYSolQND824nQmVeM1n+ZTxW2uq/ACmxhKx
S7GPk35SB0tFF/GuNzQ4kvqTkKEbBZDGAhhod7ujxfQ7Z5WmusDm7O33Vij4IrZO
W5NmCxHvd1bpIOINjBvtiIQmSnCxK7PIENCJVHuZtgxyW5kLAiD0KEVJq84hzZyQ
QD6nOc58CitvGIo43Erlv877PYXB86dd1lFW1f0pn3LliV08LhbtT6UzDP0uzHGm
m2l2GEKNg8w=
=juiT
- -----END PGP SIGNATURE-----


- --------------------------------------------------------------------------------


- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: OpenShift Container Platform 4.3.25 containernetworking-plugins security update
Advisory ID:       RHSA-2020:2443-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2443
Issue date:        2020-06-17
CVE Names:         CVE-2020-10749 
=====================================================================

1. Summary:

An update for containernetworking-plugins is now available for Red Hat
OpenShift Container Platform 4.3.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat OpenShift Container Platform 4.3 - ppc64le, s390x, x86_64

3. Description:

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

Security Fix(es):

* containernetworking/plugins: A vulnerability in IPv4 networking
implementations allowed malicious containers in Kubernetes clusters to
perform man-in-the-middle (MitM) attacks by redirecting traffic to the
malicious container with â\x{128}\x{156}rogueâ\x{128}\x{157} IPv6 router advertisements.
(CVE-2020-10749)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For OpenShift Container Platform 4.3 see the following documentation, which
will be updated shortly for release 4.3.25, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-rel
ease-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.3/updating/updating-cluster
- - -cli.html.

5. Bugs fixed (https://bugzilla.redhat.com/):

1833220 - CVE-2020-10749 containernetworking/plugins: IPv6 router advertisements 
allow for MitM attacks on IPv4 clusters

6. Package List:

Red Hat OpenShift Container Platform 4.3:

Source:
containernetworking-plugins-0.8.6-1.rhaos4.3.el7.src.rpm

ppc64le:
containernetworking-plugins-0.8.6-1.rhaos4.3.el7.ppc64le.rpm
containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el7.ppc64le.rpm

s390x:
containernetworking-plugins-0.8.6-1.rhaos4.3.el7.s390x.rpm
containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el7.s390x.rpm

x86_64:
containernetworking-plugins-0.8.6-1.rhaos4.3.el7.x86_64.rpm
containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el7.x86_64.rpm

Red Hat OpenShift Container Platform 4.3:

Source:
containernetworking-plugins-0.8.6-1.rhaos4.3.el8.src.rpm

ppc64le:
containernetworking-plugins-0.8.6-1.rhaos4.3.el8.ppc64le.rpm
containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el8.ppc64le.rpm
containernetworking-plugins-debugsource-0.8.6-1.rhaos4.3.el8.ppc64le.rpm

s390x:
containernetworking-plugins-0.8.6-1.rhaos4.3.el8.s390x.rpm
containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el8.s390x.rpm
containernetworking-plugins-debugsource-0.8.6-1.rhaos4.3.el8.s390x.rpm

x86_64:
containernetworking-plugins-0.8.6-1.rhaos4.3.el8.x86_64.rpm
containernetworking-plugins-debuginfo-0.8.6-1.rhaos4.3.el8.x86_64.rpm
containernetworking-plugins-debugsource-0.8.6-1.rhaos4.3.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-10749
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXupzCdzjgjWX9erEAQgemQ//bdhSByTD4ridz2qEAt46DsKkqprKT5dv
ZfVYx1ng8MbwFHUK/RsVpbBfKO1YWfTGMmegK1oC5NSr9t2dqVkghQPFVtUjNAMc
ZtKIN92WOSOQYZJJxBIrTDISQRmsCoh5vcbK0jwNPpubgr6k4+f+fhIeip6zwEl/
6CVta0gQvtYZyKENZ0tGqQ8Gtty+ovxg/5y4TgmpuWyO8aF1hNAMH/icUawk/F0+
DcLmhlYqrYG+LgLJXLS5Dkd3vEvxLSAWCGV0CTQmvXbO1nYBCuSuqYD4/55CZwi6
E3d4mXmEwFTHiIFJVDr7yhK0z0wMKi0bewdELnrFTpuaAzdHrsK2+WAfTTQuMswT
W6QRLV6ciwLikdMBBMB3yiFe5aCmcDb5xjOT/JbsSgFbATprSR6I3A7086DHsVRl
4NbefKjaKfM1FZTzXkjVJbUZglUu/aE1xnfk/lXm7SExpWLm5XphEkremDxkrZiA
ZobKBv3UIwVItsUhTvPxorWs1ZQY70u8BtNit/l6XeiE2C0gN0XRCZj8HLdVbHDL
bmrJeyZUdjX6VQ7mPJs3p0eJzAm+CIQiw5sfM0rqxvFzzMeUfQtyg8T0rlbHlxSy
Dpo0XtGY/Aa6pMkYEA2Oe6yn+O7mOy2prSe1Qzt4y2oZRZNZ0lj8tuc5OSSn/kud
dPzHcNBbvW0=
=9tKD
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXuq/guNLKJtyKPYoAQjrhBAAhjpzHFDvRLnQmA3UHortr6+oUxxLEUKq
Hc7XSSi2RcSG2+owlhcFLoegnlUcYqVjh/ibwxLDRiydyTHKUcEhet660XL9n+N2
ZqbomWUeiFo96rD6vTraPApGhsXu6w3bb140Nc/pgjrXHwbYKRUXEjRb9MPgbE9o
HLEOzGmysXizmb36Q0XrSzPY3gK9Z7uMrPOMZzaJJBp/I2B2y1B6D1ORibWosI2i
3id28nKgBfH5L9JFvS1Lf7AvJfgyEUK3SSTFu4ucKqUui/piDBDvmGZITGXuffXw
Vd0ZW76B1gGzLmdtUCNQO99SEauY7BNOCpcmaX9HObnHPbUTn/EL8ALBVB1htMfr
hvjnpDKLAe5pNzXLwvwMjQLDpqm6PZqorRtdnrzrFXe9lPpxeQPKUYTYOm47Y30I
XOaszTpMt4rtoPyr3j9CwNU1gwZphbaiFRbfk+JUCG1t+NO9N3C07rRx4Y++grmW
bExOjl4SdeSZN3eBuMFrN45zixQrcn/jbgGv4n+v3DkoMV99JGq9vfaQXCYAmvAH
eXiMGiAsH5avW/nbmhPVC0Y003Nenr5g7r4DcFBTP5PiRddDGOy4MVOhssSuFPrB
CNUskA5o+I0KIsJAx/uhPSQqoqkDN7HzCMgkGng7b4gCbIxoQ/k2nJRy1YQ8SiTk
SmisLo7akqM=
=QJx5
-----END PGP SIGNATURE-----