Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE Leap 15.2: 2021:0416-1 Moderate: connman Buffer Overflow

opensuse
Calendar Grey March 16, 2021
Dist Opensuse Esm H88
Resolves a couple of notable bugs in connman for openSUSE 15.2, tackling memory corruption and DNS vulnerabilities.
An update that fixes two vulnerabilities is now available

Description

This update for connman fixes the following issues:

Update to 1.39 (boo#1181751):

* Fix issue with scanning state synchronization and iwd.

* Fix issue with invalid key with 4-way handshake offloading.

* Fix issue with DNS proxy length checks to prevent buffer overflow.

(CVE-2021-26675)

* Fix issue with DHCP leaking stack data via uninitialized variable.

(CVE-2021-26676)

Update to 1.38:

* Fix issue with online check on IP address update.

* Fix issue with OpenVPN and encrypted private keys.

* Fix issue with finishing of VPN connections.

* Add support for updated stable iwd APIs.

* Add support for WireGuard networks.

Update to 1.37:

* Fix issue with handling invalid gateway addresses.

* Fix issue with handling updates of default gateway.

* Fix issue with DHCP servers that require broadcast flag.

* Add support for option to use gateways as time servers.

* Add support for option to select default technology.

* Add...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-416=1

Package List

- openSUSE Leap 15.2 (x86_64):

connman-1.39-lp152.3.3.1

connman-client-1.39-lp152.3.3.1

connman-client-debuginfo-1.39-lp152.3.3.1

connman-debuginfo-1.39-lp152.3.3.1

connman-debugsource-1.39-lp152.3.3.1

connman-devel-1.39-lp152.3.3.1

connman-doc-1.39-lp152.3.3.1

connman-nmcompat-1.39-lp152.3.3.1

connman-plugin-hh2serial-gps-1.39-lp152.3.3.1

connman-plugin-hh2serial-gps-debuginfo-1.39-lp152.3.3.1

connman-plugin-iospm-1.39-lp152.3.3.1

connman-plugin-iospm-debuginfo-1.39-lp152.3.3.1

connman-plugin-l2tp-1.39-lp152.3.3.1

connman-plugin-l2tp-debuginfo-1.39-lp152.3.3.1

connman-plugin-openconnect-1.39-lp152.3.3.1

connman-plugin-openconnect-debuginfo-1.39-lp152.3.3.1

connman-plugin-openvpn-1.39-lp152.3.3.1

connman-plugin-openvpn-debuginfo-1.39-lp152.3.3.1

connman-plugin-polkit-1.39-lp152.3.3.1

connman-plugin-pptp-1.39-lp152.3.3.1

connman-plugin-pptp-debuginfo-1.39-lp152.3.3.1

connman-plugin-tist-1.39-lp152.3.3.1

connman-plugin-tist-debuginfo-1.39-lp152.3.3.1

connman-plugin-vpnc-1.39-lp152.3.3.1

connman-plugin-vpnc-debug...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-26675.html

https://www.suse.com/security/cve/CVE-2021-26676.html

https://bugzilla.suse.com/1181751

Announcement ID: openSUSE-SU-2021:0416-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here