Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE: 2019:1527-1 Important Update for RMT-Server Security Issues

opensuse
Calendar Grey June 7, 2019
Dist Opensuse Esm H88
The latest update for openSUSE rmt-server resolves two critical concerns while implementing ten improvements that bolster both security and system efficiency.
An update that solves two vulnerabilities and has 10 fixes is now available.

Description

This update for rmt-server to version 2.1.4 fixes the following issues:

- Fix duplicate nginx location in rmt-server-pubcloud (bsc#1135222)

- Mirror additional repos that were enabled during mirroring (bsc#1132690)

- Make service IDs consistent across different RMT instances (bsc#1134428)

- Make SMT data import scripts faster (bsc#1134190)

- Fix incorrect triggering of registration sharing (bsc#1129392)

- Fix license mirroring issue in some non-SUSE repositories (bsc#1128858)

- Set CURLOPT_LOW_SPEED_LIMIT to prevent downloads from getting stuck

(bsc#1107806)

- Truncate the RMT lockfile when writing a new PID (bsc#1125770)

- Fix missing trailing slashes on custom repository import from SMT

(bsc#1118745)

- Zypper authentication plugin (fate#326629)

- Instance verification plugin in rmt-server-pubcloud (fate#326629)

- Update dependencies to fix vulnerabilities in rails (CVE-2019-5419,

bsc#1129271) and nokogiri (CVE-2019-11068,...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-1527=1

Package List

- openSUSE Leap 15.0 (x86_64):

rmt-server-2.1.4-lp150.2.16.1

rmt-server-debuginfo-2.1.4-lp150.2.16.1

rmt-server-pubcloud-2.1.4-lp150.2.16.1

References

https://www.suse.com/security/cve/CVE-2019-11068.html

https://www.suse.com/security/cve/CVE-2019-5419.html

https://bugzilla.suse.com/1107806

https://bugzilla.suse.com/1117722

https://bugzilla.suse.com/1118745

https://bugzilla.suse.com/1125770

https://bugzilla.suse.com/1128858

https://bugzilla.suse.com/1129271

https://bugzilla.suse.com/1129392

https://bugzilla.suse.com/1132160

https://bugzilla.suse.com/1132690

https://bugzilla.suse.com/1134190

https://bugzilla.suse.com/1134428

https://bugzilla.suse.com/1135222

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1527-1
Rating: important
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here