Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2020:14535-1 Critical: SUSE Manager Client Tools Update

suse
Calendar Grey November 6, 2020
Dist Suse Esm H88
SUSE has released a Security Update addressing various vulnerabilities in SUSE Manager Client Tools. Key actions to consider.
An update that solves three vulnerabilities and has 8 fixes is now available

Summary

This update fixes the following issues: salt: - Properly validate eauth credentials and tokens on SSH calls made by Salt API (bsc#1178319, bsc#1178362, bsc#1178361, CVE-2020-25592, CVE-2020-17490, CVE-2020-16846) - Fix disk.blkid to avoid unexpected keyword argument '__pub_user' (bsc#1177867) - Ensure virt.update stop_on_reboot is updated with its default value - Do not break package building for systemd OSes - Drop wrong mock from chroot unit test - Support systemd versions with dot (bsc#1176294) - Fix for grains.test_core unit test - Fix file/directory user and group ownership containing UTF-8 characters (bsc#1176024) - Several changes to virtualization: - - Fix virt update when cpu and memory are changed - - Memory Tuning GSoC - - Properly fix memory setting regression in virt.update

References

#1159670 #1167907 #1169664 #1175987 #1176024

#1176294 #1176397 #1177867 #1178319 #1178361

#1178362

Cross- CVE-2020-16846 CVE-2020-17490 CVE-2020-25592

Affected Products:

SUSE Manager Ubuntu 16.04-CLIENT-TOOLS

https://www.suse.com/security/cve/CVE-2020-16846.html

https://www.suse.com/security/cve/CVE-2020-17490.html

https://www.suse.com/security/cve/CVE-2020-25592.html

https://bugzilla.suse.com/1159670

https://bugzilla.suse.com/1167907

https://bugzilla.suse.com/1169664

https://bugzilla.suse.com/1175987

https://bugzilla.suse.com/1176024

https://bugzilla.suse.com/1176294

https://bugzilla.suse.com/1176397

https://bugzilla.suse.com/1177867

https://bugzilla.suse.com/1178319

https://bugzilla.suse.com/1178361

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:14535-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here