This rpm update fixes the following security and non-security issues: - bnc#908128: Check for bad invalid name sizes (CVE-2014-8118) - bnc#906803: Create files with mode 0 (CVE-2013-6435) - bnc#892431: Honor --noglob in install mode - bnc#911228: Fix noglob patch, it broke files with space. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12: zypper in -t patch SUSE-SLE-SDK-12-2015-40 - SUSE Linux Enterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2015-40 - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2015-40 To bring your system up-to-date, use "zypper patch". Package List:
#892431 #906803 #908128 #911228
Cross- CVE-2013-6435 CVE-2014-8118
Affected Products:
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 12
https://www.suse.com/security/cve/CVE-2013-6435.html
https://www.suse.com/security/cve/CVE-2014-8118.html
https://bugzilla.suse.com/show_bug.cgi?id=892431
https://bugzilla.suse.com/show_bug.cgi?id=906803
https://bugzilla.suse.com/show_bug.cgi?id=908128
https://bugzilla.suse.com/show_bug.cgi?id=911228
Get the latest Linux and open source security news straight to your inbox.