Low: Red Hat Enterprise MRG Grid 2.3 security update

Related Vulnerabilities: CVE-2012-4462   CVE-2012-4462  

Synopsis

Low: Red Hat Enterprise MRG Grid 2.3 security update

Type/Severity

Security Advisory: Low

Topic

Updated Grid component packages that fix one security issue, multiple bugs,
and add various enhancements are now available for Red Hat Enterprise MRG
2.3 for Red Hat Enterprise Linux 5.

The Red Hat Security Response Team has rated this update as having low
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

Description

Red Hat Enterprise MRG (Messaging, Realtime, and Grid) is a next-generation
IT infrastructure for enterprise computing. MRG offers increased
performance, reliability, interoperability, and faster computing for
enterprise customers.

MRG Grid provides high-throughput computing and enables enterprises to
achieve higher peak computing capacity as well as improved infrastructure
utilization by leveraging their existing technology to build high
performance grids. MRG Grid provides a job-queueing mechanism, scheduling
policy, and a priority scheme, as well as resource monitoring and resource
management. Users submit their jobs to MRG Grid, where they are placed into
a queue. MRG Grid then chooses when and where to run the jobs based upon a
policy, carefully monitors their progress, and ultimately informs the user
upon completion.

It was found that attempting to remove a job via
"/usr/share/condor/aviary/jobcontrol.py" with CPROC in square brackets
caused condor_schedd to crash. If aviary_query_server was configured to
listen to public interfaces, this could allow a remote attacker to cause a
denial of service condition in condor_schedd. While condor_schedd was
restarted by the condor_master process after each exit, condor_master would
throttle back restarts after each crash. This would slowly increment to the
defined MASTER_BACKOFF_CEILING value (3600 seconds/1 hour, by default).
(CVE-2012-4462)

The CVE-2012-4462 issue was discovered by Daniel Horak of the Red Hat
Enterprise MRG Quality Engineering Team.

These updated packages for Red Hat Enterprise Linux 5 provide numerous
enhancements and bug fixes for the Grid component of MRG. Some of the most
important enhancements include:

  • Release of HTCondor 7.8
  • OS integration with control groups (cgroups)
  • Kerberos integration and HTML5 interactivity in the management console
  • Historical data reporting in the management console as Technology Preview
  • Job data availability from MongoDB as Technology Preview
  • Updated EC2 AMI and instance tagging support
  • Enhanced negotiation and accounting
  • Enhanced DAG workflow management
  • Enhancements to configuration inspection, node inventory, and
    configuration of walk-in or dynamic resources
  • High availability for Aviary

Space precludes documenting all of these changes in this advisory. Refer to
the Red Hat Enterprise MRG 2 Technical Notes document, available shortly
from the link in the References section, for information on these changes.

All users of the Grid capabilities of Red Hat Enterprise MRG are advised
to upgrade to these updated packages, which correct this issue, and fix
the bugs and add the enhancements noted in the Red Hat Enterprise MRG 2
Technical Notes.

Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

Affected Products

  • MRG Grid from RHUI 2 for RHEL 5 x86_64
  • Red Hat Enterprise MRG Messaging 2 for RHEL 5 x86_64
  • Red Hat Enterprise MRG Messaging 2 for RHEL 5 i386
  • MRG Grid 2 for RHEL 5 x86_64
  • MRG Grid 2 for RHEL 5 i386

Fixes

  • BZ - 486480 - [RFE] Master should send obituary from .old logs if necessary
  • BZ - 635207 - Cumin: Edit Dynamic Group Quota chart should allow editing subshares
  • BZ - 703859 - Add chart(s) showing grid utilization by accounting group [RFE]
  • BZ - 732388 - aviary query 'getSubmissionSummary' - match for owner
  • BZ - 733498 - Expose suspend/continue controls for jobs through Aviary
  • BZ - 733515 - lookup or discovery capability so that cumin can find Aviary endpoints
  • BZ - 733516 - support for proposed Aviary endpoint lookup feature
  • BZ - 739219 - Aviary does not handle job output filenames that do not contain explicit paths
  • BZ - 740774 - Condor doesn't run jobs with real number in RequestMemory classad
  • BZ - 746005 - [RFE] wallaby plumage feature
  • BZ - 748053 - preemption does not work when group quotas are in effect
  • BZ - 749569 - [RFE] the skeleton group support in ccp/s
  • BZ - 750196 - Timer to dismiss invocation banners [RFE]
  • BZ - 750818 - SELinux error (setattr) for VM/KVM universe jobs (RHEL5 only)
  • BZ - 751013 - Job receive twice signal SIGCONT after condor_continue command.
  • BZ - 752732 - list of OSes is out of frame
  • BZ - 753822 - Make condor_job_server default submission publisher
  • BZ - 755765 - RFE: Gracefully handle MAX_..._LOG configuration errors
  • BZ - 756096 - [RFE]change UNHIBERNATE default value to not wake up all the machines
  • BZ - 756384 - RFE: Add suspend/continue job operations
  • BZ - 760567 - Change of DynamicQuota causes KeyError on empty data
  • BZ - 766612 - condor_schedd.init - stop should return 0 if there is not service executable
  • BZ - 768298 - Display supported browsers in cumin [RFE]
  • BZ - 768319 - provide information of suspended jobs
  • BZ - 768328 - there is no suspend and transfer states in ns0:JobStatusType
  • BZ - 772587 - openmpiscript - A deprecated MCA parameter value 'plm_rsh_agent' (on RHEL 6.2)
  • BZ - 773434 - Some condor_ commands with valid parameter '-help' return non zero exit code
  • BZ - 782054 - VM without VNC console doesn't start
  • BZ - 782132 - openmpiscript - Command mpirun needs parameter --prefix for correct run (on RHEL 6.2)
  • BZ - 782359 - Condor HFS quota example returns "Unknown config:" from QMF
  • BZ - 782552 - Use idempotent EC2 RunInstances
  • BZ - 782553 - [RFE] Add support for EC2 Instance Resource Tagging
  • BZ - 782816 - warning messages of wallaby shell
  • BZ - 783139 - Remove job using aviary isn't handled properly
  • BZ - 783267 - [RFE] ssh_to_job for VM/Java/Sched/Local universe
  • BZ - 785283 - RFE: expose accounting group negotiation-ordering to configuration
  • BZ - 785289 - RFE: Alter semantic of GROUP_AUTOREGROUP to replicate legacy behavior
  • BZ - 786020 - condor_configure_pool + required parameters
  • BZ - 786801 - Rotation of wallaby agent logs wrongly affects old logs
  • BZ - 786815 - Time borders have no effect for list of resources, groups, users
  • BZ - 786825 - plumage_stats parameter for server raise exception
  • BZ - 787138 - Add time-stamp to yellow banner [RFE]
  • BZ - 788452 - Java issue on updated packages from condor-7.6.3-0.3 to condor-7.6.5-0.11
  • BZ - 789351 - Change cumin's charting tools to a non-flash-based solution [RFE]
  • BZ - 796406 - wallaby doesn't recognize node config change when group deleted
  • BZ - 796798 - [RFE] Make grid persona default for Cumin
  • BZ - 799129 - [RFE] Add Kerberos authentication for Cumin
  • BZ - 799382 - Grid - Quotas - CSV - 'loading' values
  • BZ - 799404 - Grid - Limits - CSV - html metadata
  • BZ - 800065 - Cumin processes sometimes do not exit and must be killed from master with SIGKILL
  • BZ - 800079 - Provide API and implementation to query submissions using a page size and age
  • BZ - 800660 - Updates for new Aviary locator support
  • BZ - 801047 - [RFE] Change default value of sasl-mech-list to 'ANONYMOUS' or 'PLAIN DIGEST-MD5' with credentials
  • BZ - 801287 - service cumin start missing pid file
  • BZ - 801632 - [RFE] wallaby shell should have a means to delete a snapshot
  • BZ - 802704 - Inventory - Filters for a value in a column in a table
  • BZ - 802799 - wallaby shell replace-* commands with empty args should clear the value in the store
  • BZ - 802821 - Support description metadata for features and snapshots in wallaby store
  • BZ - 803359 - [RFE]change UNHIBERNATE default value to not wake up all the machines
  • BZ - 803897 - RFE: advertise the accounting group that a running job matched under on the resource ad
  • BZ - 805029 - Remove slotvis functionality from cumin [RFE]
  • BZ - 805448 - bad submitter limit
  • BZ - 805581 - Number of group quota exceeded
  • BZ - 807398 - Endpoint updating for HA configurations
  • BZ - 807820 - Update wallaby packaging to use wallaby assigned uid/gid
  • BZ - 807838 - Use plumage data to provide initial reporting capabilities [RFE]
  • BZ - 809006 - Double escaping html strings
  • BZ - 809551 - [RFE] Add the ability to use keypair by name
  • BZ - 809732 - PU job is runned before slots are cleaned from previous (removed) job
  • BZ - 810982 - Enable locator support for QueryServer in RHHAv2 tools
  • BZ - 813807 - Jobs submitted from cumin through aviary show 'unknown' for enqueued column
  • BZ - 814386 - Integration of aviary for job control, submission, and job/submission queries [RFE]
  • BZ - 815820 - condor_configd is using QMF_BROKER_AUTH_MECHANISM instead of QMF_BROKER_AUTH_MECH
  • BZ - 820419 - RFE: new command show-node-config
  • BZ - 828983 - condor resource agent start operation should have verification of startup
  • BZ - 831709 - SharedPort should depend on Master
  • BZ - 831725 - Cleanup ALLOW_NEGOTIATOR* params
  • BZ - 831756 - Add ALLOW_NEGOTIATOR to the ExecuteNode feature
  • BZ - 833095 - total local resources per slot for dynamic slots is always zero
  • BZ - 833611 - The cluster-* commands always ask for a password even if only acting on the store
  • BZ - 840076 - Job history collection daemon and tool
  • BZ - 845567 - new PRE_SKIP key word in DAGMan
  • BZ - 846955 - unexpected error message from condor init.d script
  • BZ - 848344 - Problem submitting jobs from cumin via Aviary when commands have no arguments
  • BZ - 850205 - traceback when bad option is provided to wallaby
  • BZ - 850392 - RFE Update Hunting+Splitting+Defaults algorithm
  • BZ - 850555 - RFE Add  new -expand option to condor_config_val
  • BZ - 850567 - RFE Improved  the output of condor_userprio to better support hierarchical groups
  • BZ - 850838 - RFE copy PRIORITY values from the DAG input file to the JobPrio attribute in the job ClassAd
  • BZ - 851205 - schedulers list is bigger than its parent
  • BZ - 851217 - wallaby shell should detect if there are more wallaby agents on broker
  • BZ - 851222 - configd should detect if there are more wallaby agents on broker
  • BZ - 855449 - getSubmissionID by qdate with scan mode "AFTER" does not work unless the qdate supplied is an exact match of an existing qdate
  • BZ - 856646 - getSubmissionID() by qdate returning duplicates
  • BZ - 860308 - condor SEGFAULT after upgrade while using custom hostname
  • BZ - 860850 - CVE-2012-4462 condor: DoS when removing jobs via jobcontrol.py when job id is in square brackets
  • BZ - 862550 - schedd crash on local universe condor_suspend+condor_continue job
  • BZ - 864091 - wallaby list-users prints READ_ONLY instead of READ
  • BZ - 864637 - 'condor_restart -subsystem had' causes had and negotiator to shutdown
  • BZ - 867989 - Cumin missing scheduler stats
  • BZ - 871080 - Queryserver is not visible in locator
  • BZ - 881366 - Wallaby shell modify-* commands do not accept empty strings as arguments
  • BZ - 885787 - Wallaby agent exception while running in memory
  • BZ - 886448 - Aviary api examples: option --timeout leads to Traceback

CVEs

References