Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE 15-SP3: 2021:3873-1 Important: Security Update for Netcdf

suse
Calendar Grey December 2, 2021
Dist Suse Esm H88
SUSE released critical patches for netcdf that tackle several security vulnerabilities. Make sure your system is updated without delay.
An update that fixes 16 vulnerabilities is now available

Summary

This update for netcdf fixes the following issues: - Fixed multiple vulnerabilities in ezXML: CVE-2019-20007, CVE-2019-20006, CVE-2019-20201, CVE-2019-20202, CVE-2019-20199, CVE-2019-20200, CVE-2019-20198, CVE-2021-26221, CVE-2021-26222, CVE-2021-30485, CVE-2021-31229, CVE-2021-31347, CVE-2021-31348, CVE-2021-31598 (bsc#1191856) Note: * CVE-2021-26220 not relevant for netcdf: code isn't used. * CVE-2019-20005 Issue cannot be reproduced and no patch is available upstream. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3:

References

#1191856

Cross- CVE-2019-20005 CVE-2019-20006 CVE-2019-20007

CVE-2019-20198 CVE-2019-20199 CVE-2019-20200

CVE-2019-20201 CVE-2019-20202 CVE-2021-26220

CVE-2021-26221 CVE-2021-26222 CVE-2021-30485

CVE-2021-31229 CVE-2021-31347 CVE-2021-31348

CVE-2021-31598

CVSS scores:

CVE-2019-20005 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2019-20005 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2019-20006 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2019-20006 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2019-20007 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2019-20007 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3873-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here