Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2021:1778-1 Critical libcurl Security Update Released Here

suse
Calendar Grey May 25, 2021
Scroller Suse
A revision that tackles essential vulnerabilities in libu2f-host for SUSE, promoting enhanced security protocols.
An update that solves two vulnerabilities, contains one feature and has one errata is now available

Summary

This update for libu2f-host fixes the following issues: This update ships the u2f-host package (jsc#ECO-3687 bsc#1184648) Version 1.1.10 (released 2019-05-15) - Add new devices to udev rules. - Fix a potentially uninitialized buffer (CVE-2019-9578, bsc#1128140) Version 1.1.9 (released 2019-03-06) - Fix CID copying from the init response, which broke compatibility with some devices. Version 1.1.8 (released 2019-03-05) - Add udev rules - Drop 70-old-u2f.rules and use 70-u2f.rules for everything - Use a random nonce for setting up CID to prevent fingerprinting - CVE-2019-9578: Parse the response to init in a more stable way to prevent leakage of uninitialized stack memory back to the device (bsc#1128140). Version 1.1.7 (released 2019-01-08) - Fix for trusting length from device in device init.

References

#1124781 #1128140 #1184648 ECO-3687

Cross- CVE-2018-20340 CVE-2019-9578

CVSS scores:

CVE-2018-20340 (NVD) : 6.8 CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2018-20340 (SUSE): 6.4 CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2019-9578 (NVD) : 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2019-9578 (SUSE): 2.1 CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15-SP3

SUSE Linux Enterprise Module for Basesystem 15-SP2

https://www.suse.com/security/cve/CVE-2018-20340.html

https://www.suse.com/security/cve/CVE-2019-9578.html

https://bugzilla.suse.com/1124781

https://bugzilla.suse.com/1128140

https://bugzilla.suse.com/1184648

Announcement ID: SUSE-SU-2021:1755-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.