-------------------------------------------------------------------------------- Fedora EPEL Update Notification FEDORA-EPEL-2011-4509 2011-09-24 21:16:40 --------------------------------------------------------------------------------
Name : bcfg2 Product : Fedora EPEL 6 Version : 1.1.3 Release : 1.el6 URL : http://bcfg2.org Summary : A configuration management system Description : Bcfg2 helps system administrators produce a consistent, reproducible, and verifiable description of their environment, and offers visualization and reporting tools to aid in day-to-day administrative tasks. It is the fifth generation of configuration management tools developed in the Mathematics and Computer Science Division of Argonne National Laboratory.
It is based on an operational model in which the specification can be used to validate and optionally change the state of clients, but in a feature unique to bcfg2 the client's response to the specification can also be used to assess the completeness of the specification. Using this feature, bcfg2 provides an objective measure of how good a job an administrator has done in specifying the configuration of client systems. Bcfg2 is therefore built to help administrators construct an accurate, comprehensive specification.
Bcfg2 has been designed from the ground up to support gentle reconciliation between the specification and current client states. It is designed to gracefully cope with manual system modifications.
Finally, due to the rapid pace of updates on modern networks, client systems are constantly changing; if required in your environment, Bcfg2 can enable the construction of complex change management and deployment strategies.
-------------------------------------------------------------------------------- Update Information:
* Thu Sep 22 2011 Fabian Affolter mail@fabian-affolter.ch - 1.1.3-1 - Removed patch to fix CVE-2011-3211 (was fixed upstream) - Updated to new upstream version 1.1.3 * Wed Sep 07 2011 Fabian Affolter fabian@bernewireless.net - 1.1.2-2 - Added patch to fix CVE-2011-3211 * Thu Jun 02 2011 Fabian Affolter fabian@bernewireless.net - 1.1.2-1 - Updated to new upstream version 1.1.2 - Fixed #683239 * Mon Sep 27 2010 Jeffrey C. Ollie jeff@ocjtech.us - 1.1.0-2 - Update to final version * Wed Sep 07 2011 Fabian Affolter fabian@bernewireless.net - 1.1.2-2 - Added patch to fix CVE-2011-3211 * Thu Jun 02 2011 Fabian Affolter fabian@bernewireless.net - 1.1.2-1 - Updated to new upstream version 1.1.2 - Fixed #683239 * Mon Sep 27 2010 Jeffrey C. Ollie jeff@ocjtech.us - 1.1.0-2 - Update to final version -------------------------------------------------------------------------------- References:
[ 1 ] Bug #736279 - CVE-2011-3211 bcfg2 (bcfg2-server): Privilege escalation due to improper escaping of shell command data sent from client, when SSHbase plug-in enabled https://bugzilla.redhat.com/show_bug.cgi?id=736279 --------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use su -c 'yum update bcfg2' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------