Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2021:0806-1 Important: Crmsh Security Issues Resolved

suse
Calendar Grey March 17, 2021
Dist Suse Esm H88
Crucial SUSE security patch addresses various vulnerabilities in crmsh, bolstering system robustness and dependability.
An update that solves two vulnerabilities, contains one feature and has 5 fixes is now available

Summary

This update for crmsh fixes the following issues: - Update to version 4.3.0+20210219.5d1bf034: * Fix: hb_report: walk through hb_report process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571) * Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571) * Dev: analyze: Add analyze sublevel and put preflight_check in it(jsc#ECO-1658) * Dev: utils: change default file mod as 644 for str2file function * Dev: hb_report: Detect if any ocfs2 partitions exist * Dev: lock: give more specific error message when raise ClaimLockError * Fix: Replace mktemp() to mkstemp() for security * Fix: Remove the duplicate --cov-report html in tox. * Fix: fix some lint issues. * Fix: Replace utils.msg_info to task.info

References

#1154927 #1178454 #1178869 #1179999 #1180137

#1180571 #1180688 ECO-1658

Cross- CVE-2020-35459 CVE-2021-3020

CVSS scores:

CVE-2020-35459 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2020-35459 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-3020 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

SUSE Linux Enterprise High Availability 15

https://www.suse.com/security/cve/CVE-2020-35459.html

https://www.suse.com/security/cve/CVE-2021-3020.html

https://bugzilla.suse.com/1154927

https://bugzilla.suse.com/1178454

https://bugzilla.suse.com/1178869

https://bugzilla.suse.com/1179999

https://bugzilla.suse.com/1180137

https://bugzilla.suse.com/1180571

https://bugzilla.suse.com/1180688

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:0806-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here