This update for icinga2 fixes the following issues:
- Info that since version 2.12.0 following security issue is fixed:
prepare-dirs script allows for symlink attack in the icinga user
context. boo#1172171 (CVE-2020-14004)
Update to 2.12.1:
* Bugfixes
+ Core
- Fix crashes during config update #8348 #8345
- Fix crash while removing a downtime #8228
- Ensure the daemon doesn't get killed by logrotate #8170
- Fix hangup during shutdown #8211
- Fix a deadlock in Icinga DB #8168
- Clean up zombie processes during reload #8376
- Reduce check latency #8276
+ IDO
- Prevent unnecessary IDO updates #8327 #8320
- Commit IDO MySQL transactions earlier #8349
- Make sure to insert IDO program status #8330
- Improve IDO queue stats logging #8271 #8328 #8379
+ Misc
- Ensure API connections are closed properly #8293
- Prevent unnecessary...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2020-1820=1
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-1820=1
- openSUSE Backports SLE-15-SP2:
zypper in -t patch openSUSE-2020-1820=1
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-1820=1
- openSUSE Leap 15.2 (x86_64):
icinga2-2.12.1-lp152.3.3.3
icinga2-bin-2.12.1-lp152.3.3.3
icinga2-bin-debuginfo-2.12.1-lp152.3.3.3
icinga2-common-2.12.1-lp152.3.3.3
icinga2-debuginfo-2.12.1-lp152.3.3.3
icinga2-debugsource-2.12.1-lp152.3.3.3
icinga2-doc-2.12.1-lp152.3.3.3
icinga2-ido-mysql-2.12.1-lp152.3.3.3
icinga2-ido-mysql-debuginfo-2.12.1-lp152.3.3.3
icinga2-ido-pgsql-2.12.1-lp152.3.3.3
icinga2-ido-pgsql-debuginfo-2.12.1-lp152.3.3.3
nano-icinga2-2.12.1-lp152.3.3.3
vim-icinga2-2.12.1-lp152.3.3.3
- openSUSE Leap 15.1 (x86_64):
icinga2-2.12.1-lp151.2.3.4
icinga2-bin-2.12.1-lp151.2.3.4
icinga2-bin-debuginfo-2.12.1-lp151.2.3.4
icinga2-common-2.12.1-lp151.2.3.4
icinga2-debuginfo-2.12.1-lp151.2.3.4
icinga2-debugsource-2.12.1-lp151.2.3.4
icinga2-doc-2.12.1-lp151.2.3.4
icinga2-ido-mysql-2.12.1-lp151.2.3.4
icinga2-ido-mysql-debuginfo-2.12.1-lp151.2.3.4
icinga2-ido-pgsql-2.12.1-lp151.2.3.4
icinga2-ido-pgsql-debuginfo-2.12.1-lp151.2.3.4
nano-icinga2-2.12.1-lp151.2.3.4
vim-icinga2-2.12.1-lp151.2.3.4
- openSUSE Backports...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2020-14004.html
https://bugzilla.suse.com/1159869
https://bugzilla.suse.com/1172171
https://bugzilla.suse.com/1174075
--
Get the latest Linux and open source security news straight to your inbox.