Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

openSUSE: 2021:0452-1 Moderate: Connman Buffer Overflow Issue

opensuse
Calendar Grey March 20, 2021
Dist Opensuse Esm H88
Address two vulnerabilities in connman as part of openSUSE: 2021:0452-2 update. Ensure your system remains protected by implementing these fixes now.
An update that fixes two vulnerabilities is now available

Description

This update for connman fixes the following issues:

Update to 1.39 (boo#1181751):

* Fix issue with scanning state synchronization and iwd.

* Fix issue with invalid key with 4-way handshake offloading.

* Fix issue with DNS proxy length checks to prevent buffer overflow.

(CVE-2021-26675)

* Fix issue with DHCP leaking stack data via uninitialized variable.

(CVE-2021-26676)

Update to 1.38:

* Fix issue with online check on IP address update.

* Fix issue with OpenVPN and encrypted private keys.

* Fix issue with finishing of VPN connections.

* Add support for updated stable iwd APIs.

* Add support for WireGuard networks.

Update to 1.37:

* Fix issue with handling invalid gateway addresses.

* Fix issue with handling updates of default gateway.

* Fix issue with DHCP servers that require broadcast flag.

* Add support for option to use gateways as time servers.

* Add support for option to select default technology.

* Add...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2021-452=1

Package List

- openSUSE Backports SLE-15-SP2 (x86_64):

connman-1.39-bp152.4.3.1

connman-client-1.39-bp152.4.3.1

connman-devel-1.39-bp152.4.3.1

connman-doc-1.39-bp152.4.3.1

connman-nmcompat-1.39-bp152.4.3.1

connman-plugin-hh2serial-gps-1.39-bp152.4.3.1

connman-plugin-iospm-1.39-bp152.4.3.1

connman-plugin-l2tp-1.39-bp152.4.3.1

connman-plugin-openconnect-1.39-bp152.4.3.1

connman-plugin-openvpn-1.39-bp152.4.3.1

connman-plugin-polkit-1.39-bp152.4.3.1

connman-plugin-pptp-1.39-bp152.4.3.1

connman-plugin-tist-1.39-bp152.4.3.1

connman-plugin-vpnc-1.39-bp152.4.3.1

connman-plugin-wireguard-1.39-bp152.4.3.1

connman-test-1.39-bp152.4.3.1

References

https://www.suse.com/security/cve/CVE-2021-26675.html

https://www.suse.com/security/cve/CVE-2021-26676.html

https://bugzilla.suse.com/1181751

Announcement ID: openSUSE-SU-2021:0452-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here