Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

SUSE 11 SP4 & SP3: 2018:1741-1 Moderate: Cobbler Shell Escape

suse
Calendar Grey June 19, 2018
Scroller Suse
SUSE has released a Security Update to tackle a moderate vulnerability in cobbler, which contains critical fixes alongside clear installation guidelines.
An update that solves one vulnerability and has one errata is now available

Summary

This update for cobbler fixes the following issues: - CVE-2017-1000469: Escape shell parameters provided by the user for the reposync action. (bsc#1074594) - Fix for calling koan with virt_type kvm. (bsc#1090205) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-CLIENT-TOOLS: zypper in -t patch slesctsp4-cobbler-13659=1 - SUSE Linux Enterprise Server 11-SP3-CLIENT-TOOLS: zypper in -t patch slesctsp3-cobbler-13659=1 Package List: - SUSE Linux Enterprise Server 11-SP4-CLIENT-TOOLS (i586 ia64 ppc64 s390x x86_64): koan-2.2.2-0.68.3.1

References

#1074594 #1090205

Cross- CVE-2017-1000469

Affected Products:

SUSE Linux Enterprise Server 11-SP4-CLIENT-TOOLS

SUSE Linux Enterprise Server 11-SP3-CLIENT-TOOLS

https://www.suse.com/security/cve/CVE-2017-1000469.html

https://bugzilla.suse.com/1074594

https://bugzilla.suse.com/1090205

Announcement ID: SUSE-SU-2018:1741-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.