Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE 12: 2016:1146-1 Critical Update for Portus Security Issues

suse
Calendar Grey April 25, 2016
Dist Suse Esm H88
Critical patch for Portus, addressing ten vital vulnerabilities in SUSE, guarantees improved security and reliability.
An update that fixes 10 vulnerabilities is now available

Summary

Portus was updated to version 2.0.3, which brings several fixes and enhancements: - Fixed crono job when a repository could not be found. - Fixed compatibility issues with Docker 1.10 and Distribution 2.3. - Handle multiple scopes in token requests. - Add optional fields to token response. - Fixed notification events for Distribution v2.3. - Paginate through the catalog properly. - Do not remove all the repositories if fetching one fails. - Fixed SMTP setup. - Don't let crono overflow the 'log' column on the DB. - Show the actual LDAP error on invalid login. - Fixed the location of crono logs. - Always use relative paths. - Set RUBYLIB when using portusctl. - Don't count hidden teams on the admin panel. - Warn developers on unsupported docker-compose versions. - Directly invalidate LDAP logins without name and password.

References

#963326 #963327 #963328 #963563 #963604 #963608

#963617 #963625 #963627 #969943

Cross- CVE-2015-7576 CVE-2015-7577 CVE-2015-7578

CVE-2015-7579 CVE-2015-7580 CVE-2015-7581

CVE-2016-0751 CVE-2016-0752 CVE-2016-0753

CVE-2016-2098

Affected Products:

SUSE Linux Enterprise Module for Containers 12

https://www.suse.com/security/cve/CVE-2015-7576.html

https://www.suse.com/security/cve/CVE-2015-7577.html

https://www.suse.com/security/cve/CVE-2015-7578.html

https://www.suse.com/security/cve/CVE-2015-7579.html

https://www.suse.com/security/cve/CVE-2015-7580.html

https://www.suse.com/security/cve/CVE-2015-7581.html

https://www.suse.com/security/cve/CVE-2016-0751.html

https://www.suse.com/security/cve/CVE-2016-0752.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1146-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here