Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.2: 2021:1498-1 Moderate: Barrier Authentication Issues

opensuse
Calendar Grey November 22, 2021
Dist Opensuse Esm H88
Enhance authentication measures against address vulnerabilities in Barrier, providing openSUSE users with vital upgrades.
An update that fixes two vulnerabilities is now available

Description

This update for barrier fixes the following issues:

Updated to version 2.4.0:

Barrier now supports client identity verification (fixes CVE-2021-42072,

CVE-2021-42073).

Previously a malicious client could connect to Barrier server without any

authentication and send application-level messages. This made the attack

surface of Barrier significantly larger. Additionally, in case the

malicious client got possession of a valid screen name by brute forcing or

other means it could modify the clipboard contents of the server. To

support seamless upgrades from older versions of Barrier this is currently

disabled by default. The feature can be enabled in the settings dialog. If

enabled, older clients of Barrier will be rejected. Barrier now uses

SHA256 fingerprints for establishing security of encrypted SSL

connections. After upgrading client to new version the existing server

fingerprint will need to be approved again. Client and server will show

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-1498=1

Package List

- openSUSE Leap 15.2 (x86_64):

barrier-2.4.0-lp152.3.6.1

barrier-debuginfo-2.4.0-lp152.3.6.1

barrier-debugsource-2.4.0-lp152.3.6.1

References

https://www.suse.com/security/cve/CVE-2021-42072.html

https://www.suse.com/security/cve/CVE-2021-42073.html

Announcement ID: openSUSE-SU-2021:1498-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here