Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE: 2020:0585-1 Important: Resource-Agents Security Update

opensuse
Calendar Grey May 1, 2020
Dist Opensuse Esm H88
The latest update for openSUSE resource agents resolves critical security vulnerabilities, focusing on improper tempfile handling and issues related to user account generation.
An update that contains security fixes can now be installed.

Description

This update for resource-agents fixes the following issues:

- Fixed multiple vulnerabilities related to unsafe tempfile usage.

(bsc#1146690 bsc#1146691 bsc#1146692 bsc#1146766 bsc#1146776 bsc#1146784

bsc#1146785 bsc#1146787)

- Fixed issues where the ocfmon user was created with a default password

(bsc#1021689, bsc#1146687).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-585=1

Package List

- openSUSE Leap 15.1 (i586 x86_64):

ldirectord-4.3.0184.6ee15eb2-lp151.3.18.1

resource-agents-4.3.0184.6ee15eb2-lp151.3.18.1

resource-agents-debuginfo-4.3.0184.6ee15eb2-lp151.3.18.1

resource-agents-debugsource-4.3.0184.6ee15eb2-lp151.3.18.1

- openSUSE Leap 15.1 (noarch):

monitoring-plugins-metadata-4.3.0184.6ee15eb2-lp151.3.18.1

References

https://bugzilla.suse.com/1021689

https://bugzilla.suse.com/1146687

https://bugzilla.suse.com/1146690

https://bugzilla.suse.com/1146691

https://bugzilla.suse.com/1146692

https://bugzilla.suse.com/1146766

https://bugzilla.suse.com/1146776

https://bugzilla.suse.com/1146784

https://bugzilla.suse.com/1146785

https://bugzilla.suse.com/1146787

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:0585-1
Rating: important
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here