Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2021:1694-1 Moderate: Client Tools Features and Security Fixes

suse
Calendar Grey May 21, 2021
Scroller Suse
SUSE has issued a security update aimed at remedying several security vulnerabilities found in client tools, classified with a moderate level of severity.
An update that solves 11 vulnerabilities, contains one feature and has 17 fixes is now available

Summary

This update fixes the following issues: salt: - Update to Salt release version 3002.2 (jsc#ECO-3212) - Drop support for Python2. Obsoletes "python2-salt" package - Virt module updates * network: handle missing ipv4 netmask attribute * more network support * PCI/USB host devices passthrough support - Set distro requirement to oldest supported version in requirements/base.txt - Bring missing part of async batch implementation back - Always require python3-distro (bsc#1182293) - Remove deprecated warning that breaks minion execution when "server_id_use_crc" opts is missing - Remove msgpack < 1.0.0 from base requirements (bsc#1176293) - Msgpack support for version >= 1.0.0 (bsc#1171257) - Fix issue parsing errors in ansiblegate state module - Prevent command injection in the snapper module (bsc#1185281)

References

#1099976 #1171257 #1172110 #1174855 #1176293

#1177474 #1179831 #1180101 #1180818 #1181290

#1181347 #1181368 #1181550 #1181556 #1181557

#1181558 #1181559 #1181560 #1181561 #1181562

#1181563 #1181564 #1181565 #1182281 #1182293

#1182740 #1185092 #1185281 ECO-3212

Cross- CVE-2020-28243 CVE-2020-28972 CVE-2020-35662

CVE-2021-25281 CVE-2021-25282 CVE-2021-25283

CVE-2021-25284 CVE-2021-3144 CVE-2021-3148

CVE-2021-31607 CVE-2021-3197

CVSS scores:

CVE-2020-28243 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2020-28243 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2020-28972 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2020-28972 (SUSE): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Announcement ID: SUSE-SU-2021:1694-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.