Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:1971-1 Moderate: Salt Security Update Overview

suse
Calendar Grey July 21, 2020
Dist Suse Esm H88
New patch released to address three vulnerabilities in Salt, improving security and reliability for SUSE platforms. Apply suggested updates.
An update that solves three vulnerabilities and has 12 fixes is now available

Summary

This update fixes the following issues: salt: - Fix for TypeError in Tornado importer (bsc#1174165) - Require python3-distro only for TW (bsc#1173072) - Various virt backports from 3000.2 - Avoid traceback on debug logging for swarm module (bsc#1172075) - Add publish_batch to ClearFuncs exposed methods - Update to salt version 3000 See release notes: https://docs.saltproject.io/en/latest/topics/releases/3000.html - Zypperpkg: filter patterns that start with dot (bsc#1171906) - Batch mode now also correctly provides return value (bsc#1168340) - Add docker.logout to docker execution module (bsc#1165572) - Testsuite fix - Add option to enable/disable force refresh for zypper - Python3.8 compatibility changes - Prevent sporious "salt-api" stuck processes when managing SSH minions

References

#1157465 #1159284 #1162327 #1165572 #1167437

#1168340 #1169604 #1169800 #1170104 #1170288

#1170595 #1171906 #1172075 #1173072 #1174165

Cross- CVE-2019-18897 CVE-2020-11651 CVE-2020-11652

Affected Products:

SUSE Manager Tools 12

SUSE Manager Server 3.2

SUSE Manager Proxy 3.2

SUSE Linux Enterprise Point of Sale 12-SP2

SUSE Linux Enterprise Module for Advanced Systems Management 12

https://www.suse.com/security/cve/CVE-2019-18897.html

https://www.suse.com/security/cve/CVE-2020-11651.html

https://www.suse.com/security/cve/CVE-2020-11652.html

https://bugzilla.suse.com/1157465

https://bugzilla.suse.com/1159284

https://bugzilla.suse.com/1162327

https://bugzilla.suse.com/1165572

https://bugzilla.suse.com/1167437

https://bugzilla.suse.com/1168340

Announcement ID: SUSE-SU-2020:1971-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here