Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2023:4749-1 critical: Salt Bundle arbitrary code execution

suse
Calendar Grey December 14, 2023
Dist Suse Esm H88
An updated release for the SUSE Manager Salt Package addresses security loopholes related to code execution, boosting both system stability and protection.
* bsc#1213351 * bsc#1214477 * bsc#1215157 * jsc#MSQA-708

Summary

## This update fixes the following issues: venv-salt-minion: * Security fixes: * CVE-2023-34049: Arbitrary code execution via symlink attack (bsc#1215157) * Non security fixes: * Add python dateutil module to the bundle * Allow all primitive grain types for autosign_grains (bsc#1214477) * Remove non-free RNG schema file (bsc#1213351)

References

* bsc#1213351

* bsc#1214477

* bsc#1215157

* jsc#MSQA-708

Cross-

* CVE-2023-34049

CVSS scores:

* CVE-2023-34049 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.3

* openSUSE Leap 15.4

* openSUSE Leap 15.5

* SUSE Linux Enterprise Desktop 15

* SUSE Linux Enterprise Desktop 15 SP1

* SUSE Linux Enterprise Desktop 15 SP2

* SUSE Linux Enterprise Desktop 15 SP3

* SUSE Linux Enterprise Desktop 15 SP4

* SUSE Linux Enterprise Desktop 15 SP5

* SUSE Linux Enterprise High Performance Computing 15

* SUSE Linux Enterprise High Performance Computing 15 SP1

* SUSE Linux Enterprise High Performance Computing 15 SP2

* SUSE Linux Enterprise High Performance Computing 15 SP3

* SUSE Linux Enterprise High Performance Computing 15 SP4

* SUSE Linux Enterprise High Performance Computing 15 SP5

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4749-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here