SUSE Security Update: Security update for SUSE Manager
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0841-1
Rating:             important
References:         #819365 
Cross-References:   CVE-2013-2056
Affected Products:
                    SUSE Manager 1.7 for SLE 11 SP2
                    SUSE Manager 1.2 for SLE 11 SP1
______________________________________________________________________________

   An update that fixes one vulnerability is now available. It
   includes one version update.

Description:


   spacewalk-backend has been updated to fix an authentication
   checking  problem. (bnc#819365, CVE-2013-2056)

   Security Issue reference:

   * CVE-2013-2056
   


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Manager 1.7 for SLE 11 SP2:

      zypper in -t patch sleman17sp2-spacewalk-backend-7746

   - SUSE Manager 1.2 for SLE 11 SP1:

      zypper in -t patch sleman12sp1-spacewalk-backend-7748

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Manager 1.7 for SLE 11 SP2 (x86_64) [New Version: 1.7.38.24]:

      spacewalk-backend-1.7.38.24-0.7.1
      spacewalk-backend-app-1.7.38.24-0.7.1
      spacewalk-backend-applet-1.7.38.24-0.7.1
      spacewalk-backend-config-files-1.7.38.24-0.7.1
      spacewalk-backend-config-files-common-1.7.38.24-0.7.1
      spacewalk-backend-config-files-tool-1.7.38.24-0.7.1
      spacewalk-backend-iss-1.7.38.24-0.7.1
      spacewalk-backend-iss-export-1.7.38.24-0.7.1
      spacewalk-backend-libs-1.7.38.24-0.7.1
      spacewalk-backend-package-push-server-1.7.38.24-0.7.1
      spacewalk-backend-server-1.7.38.24-0.7.1
      spacewalk-backend-sql-1.7.38.24-0.7.1
      spacewalk-backend-sql-oracle-1.7.38.24-0.7.1
      spacewalk-backend-sql-postgresql-1.7.38.24-0.7.1
      spacewalk-backend-tools-1.7.38.24-0.7.1
      spacewalk-backend-xml-export-libs-1.7.38.24-0.7.1
      spacewalk-backend-xmlrpc-1.7.38.24-0.7.1
      spacewalk-backend-xp-1.7.38.24-0.7.1

   - SUSE Manager 1.2 for SLE 11 SP1 (x86_64):

      spacewalk-backend-1.2.74-0.60.1
      spacewalk-backend-app-1.2.74-0.60.1
      spacewalk-backend-applet-1.2.74-0.60.1
      spacewalk-backend-config-files-1.2.74-0.60.1
      spacewalk-backend-config-files-common-1.2.74-0.60.1
      spacewalk-backend-config-files-tool-1.2.74-0.60.1
      spacewalk-backend-iss-1.2.74-0.60.1
      spacewalk-backend-iss-export-1.2.74-0.60.1
      spacewalk-backend-libs-1.2.74-0.60.1
      spacewalk-backend-package-push-server-1.2.74-0.60.1
      spacewalk-backend-server-1.2.74-0.60.1
      spacewalk-backend-sql-1.2.74-0.60.1
      spacewalk-backend-sql-oracle-1.2.74-0.60.1
      spacewalk-backend-tools-1.2.74-0.60.1
      spacewalk-backend-xml-export-libs-1.2.74-0.60.1
      spacewalk-backend-xmlrpc-1.2.74-0.60.1
      spacewalk-backend-xp-1.2.74-0.60.1


References:

   https://www.suse.com/security/cve/CVE-2013-2056.html
   https://bugzilla.novell.com/819365
   https://login.microfocus.com/nidp/app/login
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:0841-1: important: SUSE Manager

May 28, 2013
An update that fixes one vulnerability is now available

Summary

spacewalk-backend has been updated to fix an authentication checking problem. (bnc#819365, CVE-2013-2056) Security Issue reference: * CVE-2013-2056 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Manager 1.7 for SLE 11 SP2: zypper in -t patch sleman17sp2-spacewalk-backend-7746 - SUSE Manager 1.2 for SLE 11 SP1: zypper in -t patch sleman12sp1-spacewalk-backend-7748 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Manager 1.7 for SLE 11 SP2 (x86_64) [New Version: 1.7.38.24]: spacewalk-backend-1.7.38.24-0.7.1 spacewalk-backend-app-1.7.38.24-0.7.1 spacewalk-backend-applet-1.7.38.24-0.7.1 spacewalk-backend-config-files-1.7.38.24-0.7.1 spacewalk-backend-config-files-common-1.7.38.24-0.7.1 spacewalk-backend-config-files-tool-1.7.38.24-0.7.1 spacewalk-backend-iss-1.7.38.24-0.7.1 spacewalk-backend-iss-export-1.7.38.24-0.7.1 spacewalk-backend-libs-1.7.38.24-0.7.1 spacewalk-backend-package-push-server-1.7.38.24-0.7.1 spacewalk-backend-server-1.7.38.24-0.7.1 spacewalk-backend-sql-1.7.38.24-0.7.1 spacewalk-backend-sql-oracle-1.7.38.24-0.7.1 spacewalk-backend-sql-postgresql-1.7.38.24-0.7.1 spacewalk-backend-tools-1.7.38.24-0.7.1 spacewalk-backend-xml-export-libs-1.7.38.24-0.7.1 spacewalk-backend-xmlrpc-1.7.38.24-0.7.1 spacewalk-backend-xp-1.7.38.24-0.7.1 - SUSE Manager 1.2 for SLE 11 SP1 (x86_64): spacewalk-backend-1.2.74-0.60.1 spacewalk-backend-app-1.2.74-0.60.1 spacewalk-backend-applet-1.2.74-0.60.1 spacewalk-backend-config-files-1.2.74-0.60.1 spacewalk-backend-config-files-common-1.2.74-0.60.1 spacewalk-backend-config-files-tool-1.2.74-0.60.1 spacewalk-backend-iss-1.2.74-0.60.1 spacewalk-backend-iss-export-1.2.74-0.60.1 spacewalk-backend-libs-1.2.74-0.60.1 spacewalk-backend-package-push-server-1.2.74-0.60.1 spacewalk-backend-server-1.2.74-0.60.1 spacewalk-backend-sql-1.2.74-0.60.1 spacewalk-backend-sql-oracle-1.2.74-0.60.1 spacewalk-backend-tools-1.2.74-0.60.1 spacewalk-backend-xml-export-libs-1.2.74-0.60.1 spacewalk-backend-xmlrpc-1.2.74-0.60.1 spacewalk-backend-xp-1.2.74-0.60.1

References

#819365

Cross- CVE-2013-2056

Affected Products:

SUSE Manager 1.7 for SLE 11 SP2

SUSE Manager 1.2 for SLE 11 SP1

https://www.suse.com/security/cve/CVE-2013-2056.html

https://bugzilla.novell.com/819365

https://login.microfocus.com/nidp/app/login

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:0841-1
Rating: important

Related News