Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

SUSE Linux Enterprise: 2021:2137-1 Important: Cryptctl DoS Issue

suse
Calendar Grey June 23, 2021
Scroller Suse
This update tackles significant vulnerabilities in cryptctl for SUSE systems and offers essential guidelines for applying patches.
An update that fixes one vulnerability is now available

Summary

This update for cryptctl fixes the following issues: Update to version 2.4: - CVE-2019-18906: Client side password hashing was equivalent to clear text password storage (bsc#1186226) - First step to use plain text password instead of hashed password. - Move repository into the SUSE github organization - in RPC server, if client comes from localhost, remember its ipv4 localhost address instead of ipv6 address - tell a record to clear expired pending commands upon saving a command result; introduce pending commands RPC test case - avoid hard coding 127.0.0.1 in host ID of alive message test; let system administrator mount and unmount disks by issuing these two commands on key server. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1186226

Cross- CVE-2019-18906

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP5

SUSE Linux Enterprise Server for SAP 12-SP4

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2019-18906.html

https://bugzilla.suse.com/1186226

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:2137-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.