Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

openSUSE 15.1: 2020:1074-1 Moderate: Salt Multiple Fixes

opensuse
Calendar Grey July 26, 2020
Dist Opensuse Esm H88
A recent openSUSE security patch for salt addresses numerous vulnerabilities, improving system resilience and operational efficiency.
An update that solves four vulnerabilities and has 7 fixes is now available.

Description

This update for salt contains the following fixes:

- Fix for TypeError in Tornado importer (bsc#1174165)

- Require python3-distro only for TW (bsc#1173072)

- Update to Salt version 3000: See release notes:

https://docs.saltproject.io/en/latest/topics/releases/3000.html

- Add docker.logout to docker execution module. (bsc#1165572)

- Add option to enable/disable force refresh for zypper.

- Add publish_batch to ClearFuncs exposed methods.

- Adds test for zypper abbreviation fix.

- Avoid segfault from "salt-api" under certain conditions of heavy load

managing SSH minions. (bsc#1169604)

- Avoid traceback on debug logging for swarm module. (bsc#1172075)

- Batch mode now also correctly provides return value. (bsc#1168340)

- Better import cache handline.

- Do not make file.recurse state to fail when msgpack 0.5.4. (bsc#1167437)

- Do not require vendored backports-abc. (bsc#1170288)

- Fix errors from unit tests due NO_MOCK and...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-1074=1

Package List

- openSUSE Leap 15.1 (noarch):

salt-bash-completion-3000-lp151.5.21.1

salt-fish-completion-3000-lp151.5.21.1

salt-zsh-completion-3000-lp151.5.21.1

- openSUSE Leap 15.1 (x86_64):

python2-salt-3000-lp151.5.21.1

python3-salt-3000-lp151.5.21.1

salt-3000-lp151.5.21.1

salt-api-3000-lp151.5.21.1

salt-cloud-3000-lp151.5.21.1

salt-doc-3000-lp151.5.21.1

salt-master-3000-lp151.5.21.1

salt-minion-3000-lp151.5.21.1

salt-proxy-3000-lp151.5.21.1

salt-ssh-3000-lp151.5.21.1

salt-standalone-formulas-configuration-3000-lp151.5.21.1

salt-syndic-3000-lp151.5.21.1

References

https://www.suse.com/security/cve/CVE-2018-15750.html

https://www.suse.com/security/cve/CVE-2018-15751.html

https://www.suse.com/security/cve/CVE-2020-11651.html

https://www.suse.com/security/cve/CVE-2020-11652.html

https://bugzilla.suse.com/1159284

https://bugzilla.suse.com/1165572

https://bugzilla.suse.com/1167437

https://bugzilla.suse.com/1168340

https://bugzilla.suse.com/1169604

https://bugzilla.suse.com/1170104

https://bugzilla.suse.com/1170288

https://bugzilla.suse.com/1171906

https://bugzilla.suse.com/1172075

https://bugzilla.suse.com/1173072

https://bugzilla.suse.com/1174165

--

Announcement ID: openSUSE-SU-2020:1074-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here