Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE: 2019:0293-1 Important: Supportutils Issues Resolved

opensuse
Calendar Grey March 6, 2019
Dist Opensuse Esm H88
openSUSE Security Update: Security update for supportutils _________________________________________
An update that solves four vulnerabilities and has 9 fixes is now available.

Description

This update for supportutils fixes the following issues:

Security issues fixed:

- CVE-2018-19640: Fixed an issue where users could kill arbitrary

processes (bsc#1118463).

- CVE-2018-19638: Fixed an issue where users could overwrite arbitrary log

files (bsc#1118460).

- CVE-2018-19639: Fixed a code execution if run with -v (bsc#1118462).

- CVE-2018-19637: Fixed an issue where static temporary filename could

allow overwriting of files (bsc#1117776).

Other issues fixed:

- Fixed invalid exit code commands (bsc#1125666).

- Included additional SUSE separation (bsc#1125609).

- Merged added listing of locked packes by zypper.

- Exclude pam.txt per GDPR by default (bsc#1112461).

- Clarified -x functionality in supportconfig(8) (bsc#1115245).

- udev service and provide the whole journal content in supportconfig

(bsc#1051797).

- supportconfig collects tuned profile settings (bsc#1071545).

- sfdisk -d no disk device specified...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-293=1

Package List

- openSUSE Leap 15.0 (noarch):

supportutils-3.1-lp150.4.3.1

References

https://www.suse.com/security/cve/CVE-2018-19637.html

https://www.suse.com/security/cve/CVE-2018-19638.html

https://www.suse.com/security/cve/CVE-2018-19639.html

https://www.suse.com/security/cve/CVE-2018-19640.html

https://bugzilla.suse.com/1043311

https://bugzilla.suse.com/1046681

https://bugzilla.suse.com/1051797

https://bugzilla.suse.com/1071545

https://bugzilla.suse.com/1105849

https://bugzilla.suse.com/1112461

https://bugzilla.suse.com/1115245

https://bugzilla.suse.com/1117776

https://bugzilla.suse.com/1118460

https://bugzilla.suse.com/1118462

https://bugzilla.suse.com/1118463

https://bugzilla.suse.com/1125609

https://bugzilla.suse.com/1125666

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:0293-1
Rating: important
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here