Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2019:0654-1 Important: Openwsman Denial of Service Risk

suse
Calendar Grey March 20, 2019
Dist Suse Esm H88
SUSE Security Patch tackles critical concerns in openwsman, implementing robust solutions for identified vulnerabilities.
An update that fixes two vulnerabilities is now available

Summary

This update for openwsman fixes the following issues: Security issues fixed: - CVE-2019-3816: Fixed a vulnerability in openwsmand deamon which could lead to arbitary file disclosure (bsc#1122623). - CVE-2019-3833: Fixed a vulnerability in process_connection() which could allow an attacker to trigger an infinite loop which leads to Denial of Service (bsc#1122623). Other issues addressed: - Added OpenSSL 1.1 compatibility - Compilation in debug mode fixed - Directory listing without authentication fixed (bsc#1092206). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15:

References

#1092206 #1122623

Cross- CVE-2019-3816 CVE-2019-3833

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

https://www.suse.com/security/cve/CVE-2019-3816.html

https://www.suse.com/security/cve/CVE-2019-3833.html

https://bugzilla.suse.com/1092206

https://bugzilla.suse.com/1122623

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0654-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here