Synopsis
Important: insights-client security update
Type/Severity
Security Advisory: Important
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for insights-client is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Red Hat Insights is a service that provides analysis of registered Red Hat-based systems. The insights-client package can gather the required data (such as installed packages, running services, or software configurations) to proactively identify threats to security, performance, and stability across your environment.
Security Fix(es):
- insights-client: unsafe handling of temporary files and directories (CVE-2023-3972)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux Server 7 x86_64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
-
Red Hat Enterprise Linux Workstation 7 x86_64
-
Red Hat Enterprise Linux Desktop 7 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 7 s390x
-
Red Hat Enterprise Linux for Power, big endian 7 ppc64
-
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
-
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le
Fixes
-
BZ - 2227027
- CVE-2023-3972 insights-client: unsafe handling of temporary files and directories
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux Server 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
x86_64 |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
x86_64 |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux Workstation 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
x86_64 |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux Desktop 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
x86_64 |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux for IBM z Systems 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
s390x |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux for Power, big endian 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
ppc64 |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux for Scientific Computing 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
x86_64 |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux for Power, little endian 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
ppc64le |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
s390x |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
ppc64 |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7
SRPM |
insights-client-3.1.9-1.el7_9.src.rpm
|
SHA-256: f093fe7f0d14a1650a23770f579eb322b1d5149818c8d2a6f0c37bb0fc17924c |
ppc64le |
insights-client-3.1.9-1.el7_9.noarch.rpm
|
SHA-256: 73a4049a89c44f7b82aa85c9a2ea36c484d6972cb6263903009bdd4827156eb8 |