Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE 15.3: 2021:2675-1 Moderate: SUSE Manager Client Tools Update

opensuse
Calendar Grey August 12, 2021
Dist Opensuse Esm H88
A new openSUSE Security Patch addresses various vulnerabilities in SUSE Manager Client Tools, bringing improvements and modifications.
An update that solves 5 vulnerabilities, contains one feature and has one errata is now available

Description

This update fixes the following issues:

ansible:

- The support level for ansible is l2, not l3

dracut-saltboot:

- Force installation of libexpat.so.1 (bsc#1188846)

- Use kernel parameters from PXE formula also for local boot

golang-github-prometheus-prometheus:

- Provide and reload firewalld configuration only for:

+ openSUSE Leap 15.0, 15.1, 15.2

+ SUSE Linux Enterprise 15, 15 SP1, 15 SP2

- Upgrade to upstream version 2.27.1 (jsc#SLE-18254)

+ Bugfix:

* SECURITY: Fix arbitrary redirects under the /new endpoint

(CVE-2021-29622, bsc#1186242)

* UI: Provide errors instead of blank page on TSDB Status Page. #8654

#8659

* TSDB: Do not panic when writing very large records to the WAL. #8790

* TSDB: Avoid panic when mmaped memory is referenced after the file is

closed. #8723

* Scaleway Discovery: Fix nil pointer dereference. #8737

* Consul Discovery: Restart no longer required...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2675=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

python2-uyuni-common-libs-4.2.5-1.15.1

python3-uyuni-common-libs-4.2.5-1.15.1

- openSUSE Leap 15.3 (noarch):

ansible-2.9.21-1.5.1

ansible-doc-2.9.21-1.5.1

ansible-test-2.9.21-1.5.1

dracut-saltboot-0.1.1627546504.96a0b3e-1.27.1

mgr-cfg-4.2.3-1.18.1

mgr-cfg-actions-4.2.3-1.18.1

mgr-cfg-client-4.2.3-1.18.1

mgr-cfg-management-4.2.3-1.18.1

mgr-custom-info-4.2.2-1.12.1

mgr-osa-dispatcher-4.2.6-1.30.1

mgr-osad-4.2.6-1.30.1

mgr-push-4.2.3-1.12.1

mgr-virtualization-host-4.2.2-1.20.1

python2-mgr-cfg-4.2.3-1.18.1

python2-mgr-cfg-actions-4.2.3-1.18.1

python2-mgr-cfg-client-4.2.3-1.18.1

python2-mgr-cfg-management-4.2.3-1.18.1

python2-mgr-osa-common-4.2.6-1.30.1

python2-mgr-osa-dispatcher-4.2.6-1.30.1

python2-mgr-osad-4.2.6-1.30.1

python2-mgr-push-4.2.3-1.12.1

python2-mgr-virtualization-common-4.2.2-1.20.1

python2-mgr-virtualization-host-4.2.2-1.20.1

python2-rhnlib-4.2.4-3.28.1

python2-spacewalk-check-4.2.12-3.44.1

python2-spacewalk-client-setup-4.2.12-3.44.1

python2-spacewalk...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-27962.html

https://www.suse.com/security/cve/CVE-2021-28146.html

https://www.suse.com/security/cve/CVE-2021-28147.html

https://www.suse.com/security/cve/CVE-2021-28148.html

https://www.suse.com/security/cve/CVE-2021-29622.html

https://bugzilla.suse.com/1175478

https://bugzilla.suse.com/1186242

https://bugzilla.suse.com/1186508

https://bugzilla.suse.com/1186581

https://bugzilla.suse.com/1186650

https://bugzilla.suse.com/1188846

Announcement ID: openSUSE-SU-2021:2675-1
Rating: moderate
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here