Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

openSUSE 15-SP3: 2021:1595-1 Moderate: Client Authentication Enhancement

opensuse
Calendar Grey December 18, 2021
Dist Opensuse Esm H88
This release targets vulnerabilities in Shield, improving user authentication to block unauthorized entry.
An update that fixes two vulnerabilities is now available

Description

This update for barrier fixes the following issues:

Updated to version 2.4.0:

Barrier now supports client identity verification (fixes CVE-2021-42072,

CVE-2021-42073).

Previously a malicious client could connect to Barrier server without any

authentication and send application-level messages. This made the attack

surface of Barrier significantly larger. Additionally, in case the

malicious client got possession of a valid screen name by brute forcing or

other means it could modify the clipboard contents of the server. To

support seamless upgrades from older versions of Barrier this is currently

disabled by default. The feature can be enabled in the settings dialog. If

enabled, older clients of Barrier will be rejected. Barrier now uses

SHA256 fingerprints for establishing security of encrypted SSL

connections. After upgrading client to new version the existing server

fingerprint will need to be approved again. Client and server will show

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2021-1595=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le x86_64):

barrier-2.4.0-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2021-42072.html

https://www.suse.com/security/cve/CVE-2021-42073.html

Announcement ID: openSUSE-SU-2021:1595-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here