Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2020:0856-1 Moderate: SUSE Manager Server 3.2 Update Advisory

suse
Calendar Grey April 2, 2020
Dist Suse Esm H88
The latest SUSE Manager Server 3.2 release tackles two vulnerabilities with security improvements. Essential updates are now accessible.
An update that solves two vulnerabilities and has 15 fixes is now available

Summary

This update fixes the following issues: py26-compat-salt: - Replace pycrypto with M2Crypto as dependency for SLE15+ (bsc#1165425) redstone-xmlrpc: - Disable external entity parsing (1790381, bsc#1164120, CVE-2020-1693) - Do not download external entities (1555429, bsc#1085414, CVE-2018-1077) spacecmd: - Bugfix: attempt to purge SSM when it is empty (bsc#1155372) spacewalk-admin: - Spell correctly "successful" and "successfully" spacewalk-backend: - When downloading repo metadata, don't add "/" to the repo url if it already ends with one (bsc#1158899) - Enhance suseProducts via ISS to fix SP migration on slave server (bsc#1159184) spacewalk-certs-tools: - Add minion option in config file to disable salt mine when generated by bootstrap script (bsc#1163001) spacewalk-client-tools:

References

#1085414 #1140332 #1155372 #1157317 #1158899

#1159184 #1160246 #1161862 #1162609 #1162683

#1163001 #1163538 #1164120 #1164563 #1164771

#1165425 #1165921

Cross- CVE-2018-1077 CVE-2020-1693

Affected Products:

SUSE Manager Server 3.2

https://www.suse.com/security/cve/CVE-2018-1077.html

https://www.suse.com/security/cve/CVE-2020-1693.html

https://bugzilla.suse.com/1085414

https://bugzilla.suse.com/1140332

https://bugzilla.suse.com/1155372

https://bugzilla.suse.com/1157317

https://bugzilla.suse.com/1158899

https://bugzilla.suse.com/1159184

https://bugzilla.suse.com/1160246

https://bugzilla.suse.com/1161862

https://bugzilla.suse.com/1162609

https://bugzilla.suse.com/1162683

https://bugzilla.suse.com/1163001

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0856-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here