openSUSE Security Update: Security update for obs-service-source_validator
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2016:1660-1
Rating:             important
References:         #967265 #967610 
Cross-References:   CVE-2016-4007
Affected Products:
                    openSUSE Leap 42.1
______________________________________________________________________________

   An update that solves one vulnerability and has one errata
   is now available.

Description:

   obs-service-source_validator was updated to fix one security issue.

   This security issue was fixed:
   - CVE-2016-4007: Several maintained source services are vulnerable to
     code/paramter injection (bsc#967265).

   This non-security issue was fixed:
   - bsc#967610: Several occurrences of uninitialized value.


Patch Instructions:

   To install this openSUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - openSUSE Leap 42.1:

      zypper in -t patch openSUSE-2016-759=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - openSUSE Leap 42.1 (noarch):

      obs-service-source_validator-0.6+git20160531.fbfe336-11.1


References:

   https://www.suse.com/security/cve/CVE-2016-4007.html
   https://bugzilla.suse.com/967265
   https://bugzilla.suse.com/967610

openSUSE: 2016:1660-1: important: obs-service-source_validator

June 22, 2016
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Description

obs-service-source_validator was updated to fix one security issue. This security issue was fixed: - CVE-2016-4007: Several maintained source services are vulnerable to code/paramter injection (bsc#967265). This non-security issue was fixed: - bsc#967610: Several occurrences of uninitialized value.

 

Patch

Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2016-759=1 To bring your system up-to-date, use "zypper patch".


Package List

- openSUSE Leap 42.1 (noarch): obs-service-source_validator-0.6+git20160531.fbfe336-11.1


References

https://www.suse.com/security/cve/CVE-2016-4007.html https://bugzilla.suse.com/967265 https://bugzilla.suse.com/967610


Severity
Announcement ID: openSUSE-SU-2016:1660-1
Rating: important
Affected Products: openSUSE Leap 42.1

Related News