Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2019:0481-1 Important: Python Package Security Update for DoS

suse
Calendar Grey February 25, 2019
Dist Suse Esm H88
SUSE has released a Security Update addressing severe vulnerabilities in python-amqp, python-oslo.messaging, and other components. Ensure your systems are up to date!
An update that solves one vulnerability and has three fixes is now available

Summary

This update for python-amqp, python-oslo.messaging, python-ovs, python-paramiko, python-psql2mysql fixes the following issues: Security issue fixed for python-paramiko: - CVE-2018-1000805: Fixed an authentication bypass (bnc#1111151). Non-security issues fixed: - python-oslo.messaging: Fixed an issue if the client tries to reconnect after connection was lost (bsc#1123054). - python-ovs: Fixed memory leak in c parser (bsc#1116437). - python-ovs: Switched away from noarch and build the C based backend (bsc#1115099). - python-psql2mysql: Update to version 0.5.0+git.1539592188.13e5d0f. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1111151 #1115099 #1116437 #1123054

Cross- CVE-2018-1000805

Affected Products:

SUSE OpenStack Cloud 7

SUSE Enterprise Storage 4

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2018-1000805.html

https://bugzilla.suse.com/1111151

https://bugzilla.suse.com/1115099

https://bugzilla.suse.com/1116437

https://bugzilla.suse.com/1123054

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0481-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here