Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2020:2571-1 Significant: Mitigation for gpg3 Vulnerability Issue

suse
Calendar Grey September 27, 2019
Dist Suse Esm H88
SUSE Security Patch for gpg2 addresses vulnerabilities related to denial-of-service attacks and enhances overall system efficiency. Discover the update process.
An update that solves one vulnerability and has one errata is now available

Summary

This update for gpg2 fixes the following issues: Security issue fixed: - CVE-2019-13050: Fixed denial-of-service attacks via big keys. (bsc#1141093) Non-security issue fixed: - Allow coredumps in X11 desktop sessions (bsc#1124847). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-2480=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-2480=1 - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger

References

#1124847 #1141093

Cross- CVE-2019-13050

Affected Products:

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Desktop 12-SP4

SUSE CaaS Platform 3.0

https://www.suse.com/security/cve/CVE-2019-13050.html

https://bugzilla.suse.com/1124847

https://bugzilla.suse.com/1141093

Announcement ID: SUSE-SU-2019:2480-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here