Alerts This Week
Warning Icon 1 938
Alerts This Week
Warning Icon 1 938

openSUSE: 2024:3656-1 moderate: etcd Remote Command Exec, DoS Issues

suse
Calendar Grey October 16, 2024
Dist Suse Esm H88
Apply the most recent SUSE etcd security patches to resolve various vulnerabilities while reinforcing overall system protection.
* bsc#1095184 * bsc#1118897 * bsc#1118898 * bsc#1118899 * bsc#1121850

Summary

## This update for etcd fixes the following issues: Update to version 3.5.12: Security fixes: * CVE-2018-16873: Fixed remote command execution in cmd/go (bsc#1118897) * CVE-2018-16874: Fixed directory traversal in cmd/go (bsc#1118898) * CVE-2018-16875: Fixed CPU denial of service in crypto/x509 (bsc#1118899) * CVE-2018-16886: Fixed improper authentication issue when RBAC and client- cert-auth is enabled (bsc#1121850) * CVE-2020-15106: Fixed panic in decodeRecord method (bsc#1174951) * CVE-2020-15112: Fixed improper checks in entry index (bsc#1174951) * CVE-2021-28235: Fixed information discosure via debug function (bsc#1210138) * CVE-2022-41723: Fixed quadratic complexity in HPACK decoding in net/http (bsc#1208270, bsc#1208297)

References

* bsc#1095184

* bsc#1118897

* bsc#1118898

* bsc#1118899

* bsc#1121850

* bsc#1174951

* bsc#1181400

* bsc#1183703

* bsc#1199031

* bsc#1208270

* bsc#1208297

* bsc#1210138

* bsc#1213229

* bsc#1217070

* bsc#1217950

* bsc#1218150

Cross-

* CVE-2018-16873

* CVE-2018-16874

* CVE-2018-16875

* CVE-2018-16886

* CVE-2020-15106

* CVE-2020-15112

* CVE-2021-28235

* CVE-2022-41723

* CVE-2023-29406

* CVE-2023-47108

* CVE-2023-48795

CVSS scores:

* CVE-2018-16873 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2018-16873 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2018-16873 ( NVD ): 8.1 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2018-16874 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Announcement ID: SUSE-SU-2024:3656-1
Release Date: 2024-10-16T11:33:45Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here