Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2021:3561-1 Moderate: DoS Risk in SUSE Manager Server 4.2

suse
Calendar Grey October 27, 2021
Scroller Suse
An essential security patch for SUSE Manager Server 4.2 addresses multiple vulnerabilities, improving overall system reliability and robustness.
An update that solves two vulnerabilities, contains two features and has 31 fixes is now available

Summary

This update fixes the following issues: cobbler: - Fixed modify_setting test to complete successfully hub-xmlrpc-api: - Use rpm systemd macro to restart service in replace of systemctl patterns-suse-manager: - Virtualization-host-formula was renamed to virtualization-formulas py26-compat-salt: - Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996) py26-compat-tornado: - Added compatibility to Enterprise Linux 8 py27-compat-salt: - Fix the regression of docker_container state module - Support querying for JSON data in external sql pillar - Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996) - Fix wrong relative paths resolution with Jinja renderer when importing subdirectories spacecmd:

References

#1171520 #1181223 #1187572 #1187998 #1188315

#1188977 #1189260 #1189422 #1189609 #1189799

#1189818 #1189933 #1190040 #1190123 #1190151

#1190164 #1190166 #1190265 #1190275 #1190276

#1190300 #1190396 #1190405 #1190455 #1190512

#1190602 #1190751 #1190820 #1191123 #1191139

#1191348 #1191551 #1191898 PM-2644 SUMA-61

Cross- CVE-2021-21996 CVE-2021-40348

CVSS scores:

CVE-2021-21996 (SUSE): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CVE-2021-40348 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

SUSE Linux Enterprise Module for SUSE Manager Server 4.2

https://www.suse.com/security/cve/CVE-2021-21996.html

https://www.suse.com/security/cve/CVE-2021-40348.html

https://bugzilla.suse.com/1171520

https://bugzilla.suse.com/1181223

Announcement ID: SUSE-SU-2021:3561-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.