Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2021:14733-1 Moderate: SUSE Manager Client Tools Security Update

suse
Calendar Grey May 21, 2021
Scroller Suse
This notification pertains to the essential security enhancement for SUSE Manager Client Utilities, targeting several vulnerabilities and corrections.
An update that solves 11 vulnerabilities, contains one feature and has 17 fixes is now available

Summary

This update fixes the following issues: salt: - Update to Salt release version 3002.2 (jsc#ECO-3212) - Drop support for Python2. Obsoletes `python2-salt` package - Virt module updates * network: handle missing ipv4 netmask attribute * more network support * PCI/USB host devices passthrough support - Set distro requirement to oldest supported version in requirements/base.txt - Bring missing part of async batch implementation back - Always require python3-distro (bsc#1182293) - Remove deprecated warning that breaks minion execution when "server_id_use_crc" opts is missing - Remove msgpack < 1.0.0 from base requirements (bsc#1176293) - Msgpack support for version >= 1.0.0 (bsc#1171257) - Fix issue parsing errors in ansiblegate state module - Prevent command injection in the snapper module (bsc#1185281)

References

#1099976 #1171257 #1172110 #1174855 #1176293

#1177474 #1179831 #1180101 #1180818 #1181290

#1181347 #1181368 #1181550 #1181556 #1181557

#1181558 #1181559 #1181560 #1181561 #1181562

#1181563 #1181564 #1181565 #1182281 #1182293

#1182740 #1185092 #1185281 ECO-3212

Cross- CVE-2020-28243 CVE-2020-28972 CVE-2020-35662

CVE-2021-25281 CVE-2021-25282 CVE-2021-25283

CVE-2021-25284 CVE-2021-3144 CVE-2021-3148

CVE-2021-31607 CVE-2021-3197

CVSS scores:

CVE-2020-28243 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2020-28243 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2020-28972 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2020-28972 (SUSE): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Announcement ID: SUSE-SU-2021:14733-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.