Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

openSUSE Leap 15.3: 2021:1520-1 Moderate Permissions Security Fix

opensuse
Calendar Grey December 2, 2021
Scroller Opensuse
The latest release for openSUSE addresses several vulnerabilities, improving overall permissions safeguarding for users on Leap 15.3.
An update that solves three vulnerabilities and has 27 fixes is now available

Description

This update for permissions fixes the following issues:

Update to version 20200127:

* Makefile: Leap 15.3 still uses /etc, so adjust the installation setup

Update to version 20181225:

* mgetty: faxq-helper now finally reside in /usr/libexec

* libksysguard5: Updated path for ksgrd_network_helper

* kdesu: Updated path for kdesud

* sbin_dirs cleanup: these binaries have already been moved to /usr/sbin

* mariadb: revert auth_pam_tool to /usr/lib{,64} again

* cleanup: revert virtualbox back to plain /usr/lib

* cleanup: remove deprecated /etc/ssh/sshd_config

* hawk_invoke is not part of newer hawk2 packages anymore

* cleanup: texlive-filesystem: public now resides in libexec

* cleanup: authbind: helper now resides in libexec

* cleanup: polkit: the agent now also resides in libexec

* libexec cleanup: 'inn' news binaries now reside in libexec

* whitelist please (boo#1183669)

* Fix enlightenment paths

* usbauth: drop compatibility...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-2021-1520=1

Package List

- openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64):

permissions-20200127-lp153.24.3.1

permissions-debuginfo-20200127-lp153.24.3.1

permissions-debugsource-20200127-lp153.24.3.1

- openSUSE Leap 15.3 (noarch):

permissions-zypp-plugin-20200127-lp153.24.3.1

References

https://www.suse.com/security/cve/CVE-2019-3687.html

https://www.suse.com/security/cve/CVE-2019-3688.html

https://www.suse.com/security/cve/CVE-2020-8013.html

https://bugzilla.suse.com/1028975

https://bugzilla.suse.com/1029961

https://bugzilla.suse.com/1093414

https://bugzilla.suse.com/1133678

https://bugzilla.suse.com/1148788

https://bugzilla.suse.com/1150345

https://bugzilla.suse.com/1150366

https://bugzilla.suse.com/1151190

https://bugzilla.suse.com/1157498

https://bugzilla.suse.com/1160285

https://bugzilla.suse.com/1160764

https://bugzilla.suse.com/1161335

https://bugzilla.suse.com/1161779

https://bugzilla.suse.com/1163588

https://bugzilla.suse.com/1167163

https://bugzilla.suse.com/1169614

https://bugzilla.suse.com/1171164

https://bugzilla.suse.com/1171173

https://bugzilla.suse.com/1171569

https://bugzilla.suse.com/1171580

https://bugzilla.suse.com/1171686

https://bugzilla.suse.com/1171879

https://bugzilla.suse.com/1171882

https://bugzilla.suse.com/1173221

https://bugzilla.suse.com/1174504

https://bugzilla.su...

Read the Full Advisory

Announcement ID: openSUSE-SU-2021:1520-1
Rating: moderate
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.