Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

SUSE Manager 4.1 Update for Important Fixes: 2021:2098-1 Moderate

suse
Calendar Grey June 21, 2021
Scroller Suse
A recent update for SUSE Manager Server version 4.1 has been released, tackling significant security issues and enhancing overall stability.
An update that solves two vulnerabilities and has 35 fixes is now available

Summary

This update fixes the following issues: cobbler: - Make `fence_ipmitool` a wrapper for `fence_ipmilan` using always `lanplus`. (bsc#1184361) - Remove unused template for `fence_ipmitool`. - Prevent some race conditions when writting tftpboot files and the destination directory is not existing. (bsc#1186124) - Fix trail stripping in case of using UTF symbols. (bsc#1184561) golang-github-prometheus-node_exporter: - Update to 1.1.2 * Bug fixes + Handle errors from disabled PSI subsystem + Sanitize strings from /sys/class/power_supply + Silence missing netclass errors + Fix ineffassign issue + Fix some noisy log lines + filesystem_freebsd: Fix label values + Fix various procfs parsing errors + Handle no data from powersupplyclass + udp_queues_linux.go: change upd to udp in two error strings

References

#1151558 #1172711 #1175216 #1178767 #1180673

#1182744 #1183573 #1183649 #1183845 #1183864

#1184005 #1184286 #1184311 #1184332 #1184351

#1184361 #1184471 #1184475 #1184561 #1184617

#1184849 #1184892 #1184929 #1184940 #1185042

#1185097 #1185281 #1185506 #1185568 #1185965

#1186025 #1186124 #1186346 #1186508 #1186765

#1186852 #1186858

Cross- CVE-2021-28657 CVE-2021-31607

CVSS scores:

CVE-2021-28657 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2021-28657 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2021-31607 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-31607 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

SUSE Linux Enterprise Module for SUSE Manager Server 4.1

Announcement ID: SUSE-SU-2021:2098-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.