Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2023:3822-2 Moderate Security Fix for Supportutils Available

suse
Calendar Grey October 18, 2023
Dist Suse Esm H88
Minor security enhancement for support-tools, addressing multiple concerns and weaknesses within SUSE Linux Enterprise.
* bsc#1181477 * bsc#1196933 * bsc#1204942 * bsc#1205533 * bsc#1206402

Summary

## This update for supportutils fixes the following issues: Security fixes: * CVE-2022-45154: Removed iSCSI passwords (bsc#1207598). Other Fixes: * Changes in version 3.1.26 * powerpc plugin to collect the slots and active memory (bsc#1210950) * A Cleartext Storage of Sensitive Information vulnerability CVE-2022-45154 * supportconfig: collect BPF information (pr#154) * Added additional iscsi information (pr#155) * Added run time detection (bsc#1213127) * Changes for supportutils version 3.1.25 * Removed iSCSI passwords CVE-2022-45154 (bsc#1207598) * powerpc: Collect lsslot,amsstat, and opal elogs (pr#149) * powerpc: collect invscout logs (pr#150) * powerpc: collect RMC status logs (pr#151) * Added missing nvme nbft commands (bsc#1211599) * Fixed invalid nvme commands (bsc#1211598)

References

* bsc#1181477

* bsc#1196933

* bsc#1204942

* bsc#1205533

* bsc#1206402

* bsc#1206608

* bsc#1207543

* bsc#1207598

* bsc#1208928

* bsc#1209979

* bsc#1210015

* bsc#1210950

* bsc#1211598

* bsc#1211599

* bsc#1213127

* jsc#PED-1703

Cross-

* CVE-2022-45154

CVSS scores:

* CVE-2022-45154 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2022-45154 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Affected Products:

* SUSE Linux Enterprise Micro 5.5

An update that solves one vulnerability, contains one feature and has 14

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2022-45154.html

* https://bugzilla.suse.com/show_bug.cgi?id=1181477

* https://bugzilla.suse.com/show_bug.cgi?id=1196933

Announcement ID: SUSE-SU-2023:3822-2
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here