Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2018:3467-1 Moderate: SMT Hostname Check Security Update

suse
Calendar Grey October 26, 2018
Dist Suse Esm H88
SUSE Security Update for smt addresses a significant concern regarding hostname verification, outlining essential patching guidelines.
An update that solves one vulnerability and has one errata is now available

Summary

SMT was updated to version 3.0.38. Following security issue was fixed: - CVE-2018-12472: Harden hostname check during sibling check by forcing double reverse lookup (bsc#1104076) Following non security issues were fixed: - Add migration path check when registration sharing is enabled - Fix sibling sync errors (bsc#1111056): - Synchronize all registered products - Handle duplicate registrations when syncing - Force resync to the sibling instance in `upgrade` and `synchronize` API calls Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2018-2481=1

References

#1104076 #1111056

Cross- CVE-2018-12472

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Module for Public Cloud 12

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2018-12472.html

https://bugzilla.suse.com/1104076

https://bugzilla.suse.com/1111056

Announcement ID: SUSE-SU-2018:3467-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here