Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2019:1381-1 Important: Rmt-Server Security Threats Addressed

suse
Calendar Grey May 30, 2019
Dist Suse Esm H88
SUSE Security Update: Security update for rmt-server _______________________________________________
An update that solves two vulnerabilities and has 10 fixes is now available

Summary

This update for rmt-server to version 2.1.4 fixes the following issues: - Fix duplicate nginx location in rmt-server-pubcloud (bsc#1135222) - Mirror additional repos that were enabled during mirroring (bsc#1132690) - Make service IDs consistent across different RMT instances (bsc#1134428) - Make SMT data import scripts faster (bsc#1134190) - Fix incorrect triggering of registration sharing (bsc#1129392) - Fix license mirroring issue in some non-SUSE repositories (bsc#1128858) - Set CURLOPT_LOW_SPEED_LIMIT to prevent downloads from getting stuck (bsc#1107806) - Truncate the RMT lockfile when writing a new PID (bsc#1125770) - Fix missing trailing slashes on custom repository import from SMT (bsc#1118745) - Zypper authentication plugin (fate#326629)

References

#1107806 #1117722 #1118745 #1125770 #1128858

#1129271 #1129392 #1132160 #1132690 #1134190

#1134428 #1135222

Cross- CVE-2019-11068 CVE-2019-5419

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15

https://www.suse.com/security/cve/CVE-2019-11068.html

https://www.suse.com/security/cve/CVE-2019-5419.html

https://bugzilla.suse.com/1107806

https://bugzilla.suse.com/1117722

https://bugzilla.suse.com/1118745

https://bugzilla.suse.com/1125770

https://bugzilla.suse.com/1128858

https://bugzilla.suse.com/1129271

https://bugzilla.suse.com/1129392

https://bugzilla.suse.com/1132160

https://bugzilla.suse.com/1132690

https://bugzilla.suse.com/1134190

https://bugzilla.suse.com/1134428

https://bugzilla.suse.com/1135222

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1381-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here