| Summary: | cockpit new security issue CVE-2021-3660 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, herman.viaene, joequant, mageia, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | cockpit-232-1.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2021-10-02 17:10:17 CEST
David Walser
2021-10-02 17:10:27 CEST
Whiteboard:
(none) =>
MGA8TOO new version pushed in mga8/9
src:
- cockpit-254-1.mga8Assignee:
bugsquad =>
qa-bugs cockpit-system-254-1.mga8 cockpit-ws-254-1.mga8 cockpit-tests-254-1.mga8 cockpit-packagekit-254-1.mga8 cockpit-networkmanager-254-1.mga8 cockpit-bridge-254-1.mga8 cockpit-storaged-254-1.mga8 cockpit-sosreport-254-1.mga8 cockpit-254-1.mga8 cockpit-doc-254-1.mga8 from cockpit-254-1.mga8.src.rpm Source RPM:
cockpit-250-1.mga9.src.rpm =>
cockpit-232-1.mga8.src.rpm MGA8-64 Plasma on Lenovo B50 No installation isues. Found https://www.unixmen.com/cockpit-a-beginner-friendly-server-administration-tool/ as a help to test this. At CLI: # systemctl -l status cockpit ● cockpit.service - Cockpit Web Service Loaded: loaded (/usr/lib/systemd/system/cockpit.service; static) Active: inactive (dead) TriggeredBy: ● cockpit.socket Docs: man:cockpit-ws(8) # systemctl start cockpit # systemctl -l status cockpit ● cockpit.service - Cockpit Web Service Loaded: loaded (/usr/lib/systemd/system/cockpit.service; static) Active: active (running) since Mon 2021-10-04 15:20:34 CEST; 5s ago TriggeredBy: ● cockpit.socket Docs: man:cockpit-ws(8) Process: 10905 ExecStartPre=/usr/libexec/cockpit-certificate-ensure (code=exited, status=0/SUCCESS) Main PID: 10927 (cockpit-tls) Tasks: 1 (limit: 9402) Memory: 1.4M CPU: 155ms CGroup: /system.slice/cockpit.service └─10927 /usr/libexec/cockpit-tls okt 04 15:20:34 mach5.hviaene.thuis systemd[1]: Starting Cockpit Web Service... okt 04 15:20:34 mach5.hviaene.thuis cockpit-certificate-ensure[10916]: /usr/libexec/cockpit-certificate-helper: regel 32: sscg: opdracht niet gevonden okt 04 15:20:34 mach5.hviaene.thuis cockpit-certificate-ensure[10917]: Generating a RSA private key okt 04 15:20:34 mach5.hviaene.thuis cockpit-certificate-ensure[10917]: ..........................................+++++ okt 04 15:20:34 mach5.hviaene.thuis cockpit-certificate-ensure[10917]: ...........+++++ okt 04 15:20:34 mach5.hviaene.thuis cockpit-certificate-ensure[10917]: writing new private key to '0-self-signed.key' okt 04 15:20:34 mach5.hviaene.thuis cockpit-certificate-ensure[10917]: ----- okt 04 15:20:34 mach5.hviaene.thuis systemd[1]: Started Cockpit Web Service. Then opened port 9090 in firewall and pointed Firefox at http://localhost:9090 Webpage opened and gives a nice overview and statistics of some aspects of the system. Good to go. Whiteboard:
(none) =>
MGA8-64-OK Validating. Keywords:
(none) =>
validated_update
Dave Hodgins
2021-10-06 20:09:44 CEST
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0467.html Resolution:
(none) =>
FIXED |