Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2007:0331 - Bug Fix Advisory
Issued:
2007-05-18
Updated:
2007-05-18

RHBA-2007:0331 - Bug Fix Advisory

  • Overview
  • Updated Packages

Synopsis

conga bug fix update

Type/Severity

Bug Fix Advisory

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated conga packages that provide critical bug fixes are now available.

Description

The Conga package is a web-based administration tool for remote cluster and
storage management.

This erratum applies the following bug fixes:

  • The borrowed Zope packages used by Conga have been patched to eliminate

a possibility of XSS attack.

  • Passwords are no longer sent back from the server in cleartext for use as

input values.

  • A form error was fixed so that Conga no longer allows for cluster

names of over 15 characters.

  • An error wherein clusters and systems could not be deleted from the

manage systems interface has been addressed.

  • Entering an incorrect password for a system no longer generates an

Unbound Local Reference exception.

  • Luci failover domain forms are no longer empty
  • The fence_xvm string in cluster.conf for virtual cluster fencing has been

corrected.

  • The advanced options parameters section has been fixed.
  • A bug where virtual services were unable for configuration has been

addressed.

  • kmod-gfs-xen is now installed when necessary.
  • The 'enable shared storage support' checkbox is now cleared when a

configuration error is encountered.

  • When configuring an outer physical cluster, it is no longer necessary to

add the fence_xvmd tag manually.

Users of Conga are advised to upgrade to these updated packages, which
apply these fixes.

Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Affected Products

  • Red Hat Enterprise Linux High Availability for x86_64 5 x86_64
  • Red Hat Enterprise Linux High Availability for x86_64 5 ia64
  • Red Hat Enterprise Linux High Availability for x86_64 5 i386
  • Red Hat Enterprise Linux High Availability (for RHEL Server) from RHUI 5 x86_64
  • Red Hat Enterprise Linux High Availability (for RHEL Server) from RHUI 5 i386

Fixes

  • BZ - 228637 - CVE-2007-1462 security alert - passwords sent back from server as input value
  • BZ - 233326 - CVE-2007-0240 Conga includes version of Zope that is vulnerable to a XSS attack
  • BZ - 236020 - Conga allows creation/rename of clusters with name greater than 15 characters
  • BZ - 236021 - Cluster cannot be deleted (from 'Manage Systems') - but no error results
  • BZ - 236025 - Entering bad password when creating a new cluster = UnboundLocalError: local variable 'e' referenced before assignment
  • BZ - 236026 - luci failover domain forms are missing/empty
  • BZ - 236027 - fence_xvm is incorrectly listed as "xmv" in virtual cluster
  • BZ - 236048 - Advanced options parameters settings don't do anything
  • BZ - 236050 - Unable to configure a virtual service
  • BZ - 236052 - kmod-gfs-xen not installed with Conga install
  • BZ - 236054 - 'enable shared storage' option cleared whenever there is a configuration error
  • BZ - 236055 - Must manually edit cluster.conf on the dom0 cluster to add "<fence_xvmd/>"

CVEs

  • CVE-2007-1462
  • CVE-2007-0240

References

(none)

Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux High Availability for x86_64 5

SRPM
conga-0.9.2-6.el5.src.rpm SHA-256: 8cba8ec0d35f10edc6ab9cbd3bb69ebf9f015672a686873e808eb7003deb3846
x86_64
luci-0.9.2-6.el5.x86_64.rpm SHA-256: 82768a48bba9dbebdb26b8a0af824cdb7310530e5fb7e69cc522ddfb80d5203a
ricci-0.9.2-6.el5.x86_64.rpm SHA-256: 27db14820b0ca5c4f41c8d97c9379c6d8035711f259fc51b5401bb4a933fe29e
ia64
luci-0.9.2-6.el5.ia64.rpm SHA-256: 5beea531a67a765143fd2064d2fa81c54212fd05e29927206138e204ea437101
ricci-0.9.2-6.el5.ia64.rpm SHA-256: 3f8da21f026babc0ef7c37d0242a7f41c693ef2a6e0114be2c795ae523205b27
i386
luci-0.9.2-6.el5.i386.rpm SHA-256: a905a9416fc8c07ef61f9d0781d13dc5afeafa0b50ec094a06f16a269192a76b
ricci-0.9.2-6.el5.i386.rpm SHA-256: e0f932a42c2a54389e6f31a8f8c4eb613f21e1205bcc024518fc672ef3a4af13

Red Hat Enterprise Linux High Availability (for RHEL Server) from RHUI 5

SRPM
conga-0.9.2-6.el5.src.rpm SHA-256: 8cba8ec0d35f10edc6ab9cbd3bb69ebf9f015672a686873e808eb7003deb3846
x86_64
luci-0.9.2-6.el5.x86_64.rpm SHA-256: 82768a48bba9dbebdb26b8a0af824cdb7310530e5fb7e69cc522ddfb80d5203a
ricci-0.9.2-6.el5.x86_64.rpm SHA-256: 27db14820b0ca5c4f41c8d97c9379c6d8035711f259fc51b5401bb4a933fe29e
i386
luci-0.9.2-6.el5.i386.rpm SHA-256: a905a9416fc8c07ef61f9d0781d13dc5afeafa0b50ec094a06f16a269192a76b
ricci-0.9.2-6.el5.i386.rpm SHA-256: e0f932a42c2a54389e6f31a8f8c4eb613f21e1205bcc024518fc672ef3a4af13

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility