Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

SUSE: 2021:3170-1 Critical: SUSE Manager Server 4.2 Issues Resolved

suse
Calendar Grey September 20, 2021
Scroller Suse
Critical update resolves security flaws in SUSE Manager Server 4.2, enhancing overall system protection and functionality.
An update that solves three vulnerabilities and has 25 fixes is now available

Summary

This update fixes the following issues: branch-network-formula: - Use kernel parameters from PXE formula also for local boot cobbler - security issues fixed: - CVE-2021-40323: Fixed an arbitrary file disclosure/Template Injection (bsc#1189458) - CVE-2021-40324: Fixed an arbitrary file write (bsc#1189458) - CVE-2021-40325: Fixed a problem with the token validation (bsc#1189458) - Please note that with these changes, a valid log data from Anamon (Red Hat Autoinstallation Process) uploaded to cobbler may be rejected: cpu-mitigations-formula: - Add SLES 15 SP3 and openSUSE Leap 15.3 to supported versions openvpn-formula: - Changed package to noarch. prometheus-exporters-formula: - Fix formula data migration with missing exporter configuration (bsc#1188136) py26-compat-salt:

References

#1171483 #1173143 #1181223 #1186281 #1186339

#1187335 #1187549 #1188032 #1188042 #1188136

#1188163 #1188193 #1188260 #1188393 #1188400

#1188503 #1188505 #1188551 #1188641 #1188647

#1188656 #1188853 #1188855 #1189011 #1189040

#1189167 #1189419 #1189458

Cross- CVE-2021-40323 CVE-2021-40324 CVE-2021-40325

Affected Products:

SUSE Linux Enterprise Module for SUSE Manager Server 4.2

https://www.suse.com/security/cve/CVE-2021-40323.html

https://www.suse.com/security/cve/CVE-2021-40324.html

https://www.suse.com/security/cve/CVE-2021-40325.html

https://bugzilla.suse.com/1171483

https://bugzilla.suse.com/1173143

https://bugzilla.suse.com/1181223

https://bugzilla.suse.com/1186281

https://bugzilla.suse.com/1186339

https://bugzilla.suse.com/1187335

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3170-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.