Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE: 2021:0714-1 Important: syncthing Major Relay Vulnerability

opensuse
Calendar Grey May 11, 2021
Dist Opensuse Esm H88
Announcement regarding syncthing's refresh, tackling significant crash flaws, and fortifying feature consistency on openSUSE platforms.
An update that fixes one vulnerability is now available

Description

This update for syncthing fixes the following issues:

Update to 1.15.0/1.15.1

* This release fixes a vulnerability where Syncthing and the relay

server can crash due to malformed relay protocol messages

(CVE-2021-21404); see GHSA-x462-89pf-6r5h. (boo#1184428)

* This release updates the CLI to use subcommands and adds the

subcommands cli (previously standalone stcli utility) and decrypt (for

offline verifying and decrypting encrypted folders).

* With this release we invite everyone to test the "untrusted

(encrypted) devices" feature. You should not use it yet on important

production data. Thus UI controls are hidden behind a feature flag.

For more information, visit:

https://forum.syncthing.net/t/testing-untrusted-encrypted-devices/16470

Update to 1.14.0

* This release adds configurable device and folder defaults.

* The output format of the /rest/db/browse endpoint has changed.

update to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2021-713=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

syncthing-1.15.1-bp152.2.3.1

syncthing-relaysrv-1.15.1-bp152.2.3.1

References

https://www.suse.com/security/cve/CVE-2021-21404.html

https://bugzilla.suse.com/1184428

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0713-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here