Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2022:3878-1 Critical: SUSE Manager Server Security Patch

suse
Calendar Grey November 4, 2022
Dist Suse Esm H88
Important update released for SUSE Manager Server 4.2 addressing various problems and improving security functionalities.
An update that solves three vulnerabilities and has 18 fixes is now available

Summary

This update fixes the following issues: hub-xmlrpc-api: - Use golang(API) = 1.18 for building on SUSE (bsc#1203599) This source fails to build with the current go1.19 on SUSE and we need to use go1.18 instead. inter-server-sync: - Version 0.2.4 * Improve memory usage and log information #17193 * Conditional insert check for FK reference exists (bsc#1202785) * Correct navigation path for table rhnerratafilechannel (bsc#1202785) locale-formula: - Update to version 0.3 * Remove .map.gz from kb_map dictionary (bsc#1203406) py27-compat-salt: - Fix state.apply in test mode with file state module on user/group checking (bsc#1202167) - Make zypperpkg to retry if RPM lock is temporarily unavailable (bsc#1200596) python-urlgrabber: - Fix wrong logic on find_proxy method causing proxy not being used (bsc#1201788)

References

#1195624 #1197724 #1199726 #1200596 #1201059

#1201788 #1202167 #1202729 #1202785 #1203283

#1203406 #1203422 #1203564 #1203599 #1203611

#1203898 #1204146 #1204203 #1204543 #1204716

#1204741

Cross- CVE-2022-31255 CVE-2022-43753 CVE-2022-43754

CVSS scores:

CVE-2022-43753 (SUSE): 5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVE-2022-43754 (SUSE): 3 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

Affected Products:

SUSE Linux Enterprise Module for SUSE Manager Server 4.2

SUSE Manager Server 4.2

https://www.suse.com/security/cve/CVE-2022-31255.html

https://www.suse.com/security/cve/CVE-2022-43753.html

https://www.suse.com/security/cve/CVE-2022-43754.html

https://bugzilla.suse.com/1195624

https://bugzilla.suse.com/1197724

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3878-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here