• 公告ID (KylinSec-SA-2024-1522)

摘要:

pcp security update

安全等级: High

公告ID: KylinSec-SA-2024-1522

发布日期: 2024年4月12日

关联CVE: CVE-2024-3019  

  • 详细介绍

1. 漏洞描述

   

PCP provides a range of services that may be used to monitor and manage system performance. These services are distributed and scalable to accommodate the most complex system configurations and performance problems.

Security Fix(es):

A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.(CVE-2024-3019)

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-3019 KY3.5.2 pcp Fixed

3. 影响组件

    pcp

4. 修复版本

   

KY3.5.2

软件名称 架构 版本号
pcp-help noarch 5.3.7-4.ky3_5.kb1
pcp-export-pcp2spark x86_64 5.3.7-4.ky3_5.kb1
pcp-selinux x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-lustre x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-libvirt x86_64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2graphite x86_64 5.3.7-4.ky3_5.kb1
perl-PCP-LogSummary x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-named x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-openmetrics x86_64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2json x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-bash x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-samba x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-dm x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-infiniband x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-dbping x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-docker x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-rsyslog x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-bind2 x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-oracle x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-news x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-hacluster x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-bpftrace x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-activemq x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-lmsensors x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-mssql x86_64 5.3.7-4.ky3_5.kb1
pcp-import-iostat2pcp x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-podman x86_64 5.3.7-4.ky3_5.kb1
pcp-devel x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-mic x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-cisco x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-elasticsearch x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-summary x86_64 5.3.7-4.ky3_5.kb1
pcp-import-ganglia2pcp x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-systemd x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-postfix x86_64 5.3.7-4.ky3_5.kb1
perl-PCP-MMV x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-openvswitch x86_64 5.3.7-4.ky3_5.kb1
pcp-import-sar2pcp x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-perfevent x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-gluster x86_64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2xml x86_64 5.3.7-4.ky3_5.kb1
pcp-conf x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-apache x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-mounts x86_64 5.3.7-4.ky3_5.kb1
pcp x86_64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2elasticsearch x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-smart x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-nvidia-gpu x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-nutcracker x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-ds389 x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-cifs x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-zimbra x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-bcc x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-nfsclient x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-logger x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-slurm x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-sockets x86_64 5.3.7-4.ky3_5.kb1
pcp-export-zabbix-agent x86_64 5.3.7-4.ky3_5.kb1
perl-PCP-PMDA x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-json x86_64 5.3.7-4.ky3_5.kb1
pcp-system-tools x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-gpsd x86_64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2zabbix x86_64 5.3.7-4.ky3_5.kb1
perl-PCP-LogImport x86_64 5.3.7-4.ky3_5.kb1
python3-pcp x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-mysql x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-netfilter x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-bonding x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-postgresql x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-shping x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-zswap x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-mongodb x86_64 5.3.7-4.ky3_5.kb1
pcp-import-mrtg2pcp x86_64 5.3.7-4.ky3_5.kb1
pcp-gui x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-snmp x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-unbound x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-gfs2 x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-bpf x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-memcache x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-weblog x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-trace x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-ds389log x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-mailq x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-lio x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-gpfs x86_64 5.3.7-4.ky3_5.kb1
pcp-import-collectl2pcp x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-pdns x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-sendmail x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-lustrecomm x86_64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2influxdb x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-haproxy x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-rabbitmq x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-nginx x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-roomtemp x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-redis x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-netcheck x86_64 5.3.7-4.ky3_5.kb1
pcp-zeroconf x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-denki x86_64 5.3.7-4.ky3_5.kb1
pcp-pmda-activemq aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-zimbra aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-infiniband aarch64 5.3.7-4.ky3_5.kb1
pcp-export-zabbix-agent aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-gfs2 aarch64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2json aarch64 5.3.7-4.ky3_5.kb1
pcp-import-collectl2pcp aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-cifs aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-mounts aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-bpftrace aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-sendmail aarch64 5.3.7-4.ky3_5.kb1
pcp-import-sar2pcp aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-bpf aarch64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2graphite aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-gpsd aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-dbping aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-lustrecomm aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-openmetrics aarch64 5.3.7-4.ky3_5.kb1
pcp-zeroconf aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-ds389log aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-apache aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-cisco aarch64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2influxdb aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-oracle aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-hacluster aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-shping aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-mysql aarch64 5.3.7-4.ky3_5.kb1
perl-PCP-LogSummary aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-rabbitmq aarch64 5.3.7-4.ky3_5.kb1
pcp-import-iostat2pcp aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-roomtemp aarch64 5.3.7-4.ky3_5.kb1
pcp-import-mrtg2pcp aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-mongodb aarch64 5.3.7-4.ky3_5.kb1
pcp-import-ganglia2pcp aarch64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2zabbix aarch64 5.3.7-4.ky3_5.kb1
pcp-devel aarch64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2spark aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-podman aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-json aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-haproxy aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-trace aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-redis aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-libvirt aarch64 5.3.7-4.ky3_5.kb1
pcp-system-tools aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-nfsclient aarch64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2xml aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-weblog aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-systemd aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-lio aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-news aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-mic aarch64 5.3.7-4.ky3_5.kb1
perl-PCP-PMDA aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-postgresql aarch64 5.3.7-4.ky3_5.kb1
perl-PCP-MMV aarch64 5.3.7-4.ky3_5.kb1
pcp-export-pcp2elasticsearch aarch64 5.3.7-4.ky3_5.kb1
pcp-gui aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-zswap aarch64 5.3.7-4.ky3_5.kb1
python3-pcp aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-lmsensors aarch64 5.3.7-4.ky3_5.kb1
pcp-selinux aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-postfix aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-pdns aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-summary aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-nutcracker aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-rsyslog aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-slurm aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-gluster aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-docker aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-gpfs aarch64 5.3.7-4.ky3_5.kb1
pcp-conf aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-bonding aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-elasticsearch aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-mailq aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-netfilter aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-perfevent aarch64 5.3.7-4.ky3_5.kb1
pcp aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-samba aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-sockets aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-netcheck aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-dm aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-ds389 aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-snmp aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-logger aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-nvidia-gpu aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-named aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-bind2 aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-lustre aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-openvswitch aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-nginx aarch64 5.3.7-4.ky3_5.kb1
perl-PCP-LogImport aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-bash aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-memcache aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-smart aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-denki aarch64 5.3.7-4.ky3_5.kb1
pcp-pmda-unbound aarch64 5.3.7-4.ky3_5.kb1

5. 修复方法


方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm

方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名

6. 下载链接

   

KY3.5.2:

x86_64:

     pcp-help   

     pcp-export-pcp2spark   

     pcp-selinux   

     pcp-pmda-lustre   

     pcp-pmda-libvirt   

     pcp-export-pcp2graphite   

     perl-PCP-LogSummary   

     pcp-pmda-named   

     pcp-pmda-openmetrics   

     pcp-export-pcp2json   

     pcp-pmda-bash   

     pcp-pmda-samba   

     pcp-pmda-dm   

     pcp-pmda-infiniband   

     pcp-pmda-dbping   

     pcp-pmda-docker   

     pcp-pmda-rsyslog   

     pcp-pmda-bind2   

     pcp-pmda-oracle   

     pcp-pmda-news   

     pcp-pmda-hacluster   

     pcp-pmda-bpftrace   

     pcp-pmda-activemq   

     pcp-pmda-lmsensors   

     pcp-pmda-mssql   

     pcp-import-iostat2pcp   

     pcp-pmda-podman   

     pcp-devel   

     pcp-pmda-mic   

     pcp-pmda-cisco   

     pcp-pmda-elasticsearch   

     pcp-pmda-summary   

     pcp-import-ganglia2pcp   

     pcp-pmda-systemd   

     pcp-pmda-postfix   

     perl-PCP-MMV   

     pcp-pmda-openvswitch   

     pcp-import-sar2pcp   

     pcp-pmda-perfevent   

     pcp-pmda-gluster   

     pcp-export-pcp2xml   

     pcp-conf   

     pcp-pmda-apache   

     pcp-pmda-mounts   

     pcp   

     pcp-export-pcp2elasticsearch   

     pcp-pmda-smart   

     pcp-pmda-nvidia-gpu   

     pcp-pmda-nutcracker   

     pcp-pmda-ds389   

     pcp-pmda-cifs   

     pcp-pmda-zimbra   

     pcp-pmda-bcc   

     pcp-pmda-nfsclient   

     pcp-pmda-logger   

     pcp-pmda-slurm   

     pcp-pmda-sockets   

     pcp-export-zabbix-agent   

     perl-PCP-PMDA   

     pcp-pmda-json   

     pcp-system-tools   

     pcp-pmda-gpsd   

     pcp-export-pcp2zabbix   

     perl-PCP-LogImport   

     python3-pcp   

     pcp-pmda-mysql   

     pcp-pmda-netfilter   

     pcp-pmda-bonding   

     pcp-pmda-postgresql   

     pcp-pmda-shping   

     pcp-pmda-zswap   

     pcp-pmda-mongodb   

     pcp-import-mrtg2pcp   

     pcp-gui   

     pcp-pmda-snmp   

     pcp-pmda-unbound   

     pcp-pmda-gfs2   

     pcp-pmda-bpf   

     pcp-pmda-memcache   

     pcp-pmda-weblog   

     pcp-pmda-trace   

     pcp-pmda-ds389log   

     pcp-pmda-mailq   

     pcp-pmda-lio   

     pcp-pmda-gpfs   

     pcp-import-collectl2pcp   

     pcp-pmda-pdns   

     pcp-pmda-sendmail   

     pcp-pmda-lustrecomm   

     pcp-export-pcp2influxdb   

     pcp-pmda-haproxy   

     pcp-pmda-rabbitmq   

     pcp-pmda-nginx   

     pcp-pmda-roomtemp   

     pcp-pmda-redis   

     pcp-pmda-netcheck   

     pcp-zeroconf   

     pcp-pmda-denki   

aarch64:

     pcp-help   

     pcp-pmda-activemq   

     pcp-pmda-zimbra   

     pcp-pmda-infiniband   

     pcp-export-zabbix-agent   

     pcp-pmda-gfs2   

     pcp-export-pcp2json   

     pcp-import-collectl2pcp   

     pcp-pmda-cifs   

     pcp-pmda-mounts   

     pcp-pmda-bpftrace   

     pcp-pmda-sendmail   

     pcp-import-sar2pcp   

     pcp-pmda-bpf   

     pcp-export-pcp2graphite   

     pcp-pmda-gpsd   

     pcp-pmda-dbping   

     pcp-pmda-lustrecomm   

     pcp-pmda-openmetrics   

     pcp-zeroconf   

     pcp-pmda-ds389log   

     pcp-pmda-apache   

     pcp-pmda-cisco   

     pcp-export-pcp2influxdb   

     pcp-pmda-oracle   

     pcp-pmda-hacluster   

     pcp-pmda-shping   

     pcp-pmda-mysql   

     perl-PCP-LogSummary   

     pcp-pmda-rabbitmq   

     pcp-import-iostat2pcp   

     pcp-pmda-roomtemp   

     pcp-import-mrtg2pcp   

     pcp-pmda-mongodb   

     pcp-import-ganglia2pcp   

     pcp-export-pcp2zabbix   

     pcp-devel   

     pcp-export-pcp2spark   

     pcp-pmda-podman   

     pcp-pmda-json   

     pcp-pmda-haproxy   

     pcp-pmda-trace   

     pcp-pmda-redis   

     pcp-pmda-libvirt   

     pcp-system-tools   

     pcp-pmda-nfsclient   

     pcp-export-pcp2xml   

     pcp-pmda-weblog   

     pcp-pmda-systemd   

     pcp-pmda-lio   

     pcp-pmda-news   

     pcp-pmda-mic   

     perl-PCP-PMDA   

     pcp-pmda-postgresql   

     perl-PCP-MMV   

     pcp-export-pcp2elasticsearch   

     pcp-gui   

     pcp-pmda-zswap   

     python3-pcp   

     pcp-pmda-lmsensors   

     pcp-selinux   

     pcp-pmda-postfix   

     pcp-pmda-pdns   

     pcp-pmda-summary   

     pcp-pmda-nutcracker   

     pcp-pmda-rsyslog   

     pcp-pmda-slurm   

     pcp-pmda-gluster   

     pcp-pmda-docker   

     pcp-pmda-gpfs   

     pcp-conf   

     pcp-pmda-bonding   

     pcp-pmda-elasticsearch   

     pcp-pmda-mailq   

     pcp-pmda-netfilter   

     pcp-pmda-perfevent   

     pcp   

     pcp-pmda-samba   

     pcp-pmda-sockets   

     pcp-pmda-netcheck   

     pcp-pmda-dm   

     pcp-pmda-ds389   

     pcp-pmda-snmp   

     pcp-pmda-logger   

     pcp-pmda-nvidia-gpu   

     pcp-pmda-named   

     pcp-pmda-bind2   

     pcp-pmda-lustre   

     pcp-pmda-openvswitch   

     pcp-pmda-nginx   

     perl-PCP-LogImport   

     pcp-pmda-bash   

     pcp-pmda-memcache   

     pcp-pmda-smart   

     pcp-pmda-denki   

     pcp-pmda-unbound   

上一篇:KylinSec-SA-2024-1521 下一篇:KylinSec-SA-2024-1523