Re: CVE-2016-5393: Apache Hadoop Privilege escalation vulnerability

Yongjun Zhang <yzhang-psgPW5cihnJWk0Htik3J/[email protected]>
Newsgroups gmane.comp.security.bugtraq,gmane.comp.security.oss.general,gmane.comp.apache.webservices.general
Message-ID <CAA0W1bQ9jnVcNYZK8i-fGYtc=VUiYm_H+TxqkjY3Tfuwb1kwMQ__33617.8474165083$1480436307$gmane$org@mail.gmail.com>
Hi Zhe,

Please refer to  https://www.apache.org/security/ for details.

Thanks.

--Yongjun

On Mon, Nov 28, 2016 at 10:26 PM, Zhe Zhang <[email protected]>
wrote:

> Thanks for the note Yongjun! Does HADOOP-13434
> <https://issues.apache.org/jira/browse/HADOOP-13434> fix the problem?
>
> On Mon, Nov 28, 2016 at 4:04 PM Yongjun Zhang <[email protected]>
> wrote:
>
> > Hi,
> >
> > Please see below the official announcement of a critical security
> > vulnerability that's discovered and subsequently fixed in Apache Hadoop
> > releases.
> >
> > Thanks and best regards,
> >
> > --Yongjun
> >
> > ----------
> >
> > CVE-2016-5393: Apache Hadoop Privilege escalation vulnerability
> >
> > Severity: Critical
> >
> >
> >
> > Vendor:
> >
> > The Apache Software Foundation
> >
> >
> >
> > Versions Affected:
> >
> > Hadoop 2.6.x, 2.7.x
> >
> >
> >
> > Description:
> >
> > A remote user who can authenticate with the HDFS NameNode can possibly
> run
> > arbitrary commands as the hdfs user.
> >
> >
> >
> > Mitigation:
> >
> > 2.7.x users should upgrade to 2.7.3
> >
> > 2.6.x users should upgrade to 2.6.5
> >
> >
> >
> > Impact:
> >
> > A remote user who can authenticate with the HDFS NameNode can possibly
> run
> > arbitrary commands with the same privileges as HDFS service.
> >
> >
> >
> > Credit:
> >
> > This issue was discovered by Freddie Rice.
> >
> > ----------
> >
> --
> Zhe Zhang
> Apache Hadoop Committer
> http://zhe-thoughts.github.io/about/ | @oldcap
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.