Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:14404-1 Moderate: Salt-Client & Spacecmd Security Issues

suse
Calendar Grey June 23, 2020
Dist Suse Esm H88
SUSE Security Update addresses multiple vulnerabilities in SUSE Manager Client Tools, providing 10 essential patches ready for user application.
An update that solves two vulnerabilities and has 10 fixes is now available

Summary

This update fixes the following issues: salt: - Require python3-distro only for TW (bsc#1173072) - Various virt backports from 3000.2 - Avoid traceback on debug logging for swarm module (bsc#1172075) - Add publish_batch to ClearFuncs exposed methods - Zypperpkg: filter patterns that start with dot (bsc#1171906) - Batch mode now also correctly provides return value (bsc#1168340) - Add docker.logout to docker execution module (bsc#1165572) - Testsuite fix - Add option to enable/disable force refresh for zypper - Python3.8 compatibility changes - Prevent sporious "salt-api" stuck processes when managing SSH minions because of logging deadlock (bsc#1159284) - Avoid segfault from "salt-api" under certain conditions of heavy load managing SSH minions (bsc#1169604)

References

#1159284 #1165572 #1168340 #1169604 #1169800

#1170104 #1170288 #1170595 #1171687 #1171906

#1172075 #1173072

Cross- CVE-2020-11651 CVE-2020-11652

Affected Products:

SUSE Manager Ubuntu 16.04-CLIENT-TOOLS-BETA

https://www.suse.com/security/cve/CVE-2020-11651.html

https://www.suse.com/security/cve/CVE-2020-11652.html

https://bugzilla.suse.com/1159284

https://bugzilla.suse.com/1165572

https://bugzilla.suse.com/1168340

https://bugzilla.suse.com/1169604

https://bugzilla.suse.com/1169800

https://bugzilla.suse.com/1170104

https://bugzilla.suse.com/1170288

https://bugzilla.suse.com/1170595

https://bugzilla.suse.com/1171687

https://bugzilla.suse.com/1171906

https://bugzilla.suse.com/1172075

https://bugzilla.suse.com/1173072

Announcement ID: SUSE-SU-2020:14404-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here