Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

openSUSE Leap 15.2 Security Update for rmt-server: Important Patch

opensuse
Calendar Grey November 21, 2020
Dist Opensuse Esm H88
An important update for openSUSE's rmt-server addresses critical vulnerabilities, enhancing performance and security with comprehensive patch guidelines
An update that fixes 16 vulnerabilities is now available.

Description

This update for rmt-server fixes the following issues:

Update to version 2.6.5:

- Solved potential bug of SCC repository URLs changing over time. RMT now

self heals by removing the previous invalid repository and creating the

correct one.

- Add web server settings to /etc/rmt.conf: Now it's possible to configure

the minimum and maximum threads count as well the number of web server

workers to be booted through /etc/rmt.conf.

- Instead of using an MD5 of URLs for custom repository friendly_ids, RMT

now builds an ID from the name.

- Fix RMT file caching based on timestamps: Previously, RMT sent GET

requests with the header 'If-Modified-Since' to a repository server and

if the response had a 304 (Not Modified), it would copy a file from the

local cache instead of downloading. However, if the local file timestamp

accidentally changed to a date newer than the one on the repository

server, RMT would have...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1993=1

Package List

- openSUSE Leap 15.2 (x86_64):

rmt-server-2.6.5-lp152.2.3.1

rmt-server-config-2.6.5-lp152.2.3.1

rmt-server-debuginfo-2.6.5-lp152.2.3.1

rmt-server-debugsource-2.6.5-lp152.2.3.1

rmt-server-pubcloud-2.6.5-lp152.2.3.1

References

https://www.suse.com/security/cve/CVE-2019-16770.html

https://www.suse.com/security/cve/CVE-2019-5418.html

https://www.suse.com/security/cve/CVE-2019-5419.html

https://www.suse.com/security/cve/CVE-2019-5420.html

https://www.suse.com/security/cve/CVE-2020-11076.html

https://www.suse.com/security/cve/CVE-2020-11077.html

https://www.suse.com/security/cve/CVE-2020-15169.html

https://www.suse.com/security/cve/CVE-2020-5247.html

https://www.suse.com/security/cve/CVE-2020-5249.html

https://www.suse.com/security/cve/CVE-2020-5267.html

https://www.suse.com/security/cve/CVE-2020-8164.html

https://www.suse.com/security/cve/CVE-2020-8165.html

https://www.suse.com/security/cve/CVE-2020-8166.html

https://www.suse.com/security/cve/CVE-2020-8167.html

https://www.suse.com/security/cve/CVE-2020-8184.html

https://www.suse.com/security/cve/CVE-2020-8185.html

https://bugzilla.suse.com/1165548

https://bugzilla.suse.com/1168554

https://bugzilla.suse.com/1172177

https://bugzilla.suse.com/1172182

https://bugzilla.suse.com/117218...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1993-1
Rating: important
Affected Products: openSUSE Leap 15.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here