|
Message-ID: <CAC-pSX1Lv8iv1ZKbi0++WtG-WaJSPZj-7r+o6pYBryMKxxqMNQ@mail.gmail.com> Date: Wed, 24 Oct 2018 12:11:35 -0700 From: Jim Apple <jbapple@...udera.com> To: oss-security@...ts.openwall.com Subject: Fwd: CVE-2018-11785 and CVE-2018-11792, was "[ANNOUNCE] Apache Impala 3.0.1 release" Apache Impala just released version 3.0.1 to fix CVE-2018-11785 and CVE-2018-11792 ---------- Forwarded message --------- From: Jim Apple <jbapple@...udera.com> Date: Wed, Oct 24, 2018 at 12:09 PM Subject: CVE-2018-11785 and CVE-2018-11792, was "[ANNOUNCE] Apache Impala 3.0.1 release" To: <user@...ala.apache.org>, dev@...ala <dev@...ala.apache.org>, Michael Ho <kwho@...udera.com>, Fredy Wijaya <fwijaya@...udera.com>, < security@...che.org> Additionally, this release was mainly to pick up two security fixes: CVE-2018-11785: - Missing authorization check in Apache Impala allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query CVE-2018-11792 (IMPALA-7502): - ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database On Wed, Oct 24, 2018 at 12:05 PM Jim Apple <jbapple@...udera.com> wrote: > The Apache Impala PMC is announcing the release of Impala 3.0.1. > > Impala is a high-performance distributed SQL engine. > > The release is available at https://impala.apache.org/downloads.html > > Thanks, > Jim Apple on behalf of the Apache Impala PMC > >
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.