From ${URL} : Ganeti, an open source virtualization manager, suffers from multiple issues in its RESTful control interface (RAPI). The distributed replicated storage (DRBD) secret is leaked by the RAPI interface when job results are requested. Leveraging on the knowledge of this secret, a malicious user who had already gained access to the storage network of the cluster can retrieve instance data more easily and reliably. The RAPI interface is also vulnerable to a DoS condition, triggered via SSL parameter renegotiation issued by a malicious client. The condition leads to resource exhaustion on the master node. Affected version: Ganeti <=2.9.6, <=2.10.7, <=2.11.7, <=2.12.5, <=2.13.2, <=2.14.1, <=2.15.1 Fixed version: Ganeti >=2.9.7, >=2.10.8, >=2.11.8, >=2.12.6, >=2.13.3, >=2.14.2, >=2.15.2 Credit: vulnerability reported by Pierre Kim <pierre [dot] kim [dot] sec [at] gmail [dot] com>. CVE: CVE-2015-7944 (DoS), CVE-2015-7945 (DRBD secret leak) Timeline: 2015-12-21: vulnerability report received 2015-12-24: contacted affected vendors 2015-12-30: advisory release References: http://downloads.ganeti.org/releases Permalink: http://www.ocert.org/advisories/ocert-2015-012.html @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
2.15.2 is in the tree. @maintainers, bump for action.
2.15.2 is ready for stabilization
@ Arches, please test and mark stable: =app-emulation/ganeti-2.15.2-r5
@chutzpah Repoman complains because there are some missing stable packages. Could you provide a full list? thanks.
amd64 stable
x86 stable. Maintainer(s), please cleanup. Security, please vote.
Done. https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=260a9b7b4570e9993ca3a957be6f4b24a288d9e2
GLSA Vote: No