Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 202501:15286-1 Moderate: Client Tools security threat update

suse
Calendar Grey February 14, 2025
Dist Suse Esm H88
Maintenance release for SUSE Manager Client Tools, tackling moderate concerns and remedies for Ubuntu 20.04 users.
* bsc#1228182 * bsc#1228690 * bsc#1229079 * bsc#1229104 * bsc#1230361

Summary

## This update fixes the following issues: salt: * Build all python bindings for all flavors * Fixed the condition of alternatives for Tumbleweed and Leap 16 * Handle logger exception when flushing already closed file * Included passlib as a recommended dependency * Make minion reconnecting on changing master IP (bsc#1228182) * Make Salt Bundle more tolerant to long running jobs (bsc#1228690) * Removed System V init support * Reverted setting SELinux context for minion service (bsc#1233667) * Use update-alternatives for salt-call and fix builing on EL8 scap-security-guide was updated to version 0.1.75 (jsc#ECO-3319): * Added Ism profile for OL8, OL9 * Added new product kylinserver10 * Created OL10 product * Release SLMicro5 product * Replaced two date injections by SOURCE_DATE_EPOCH to make reproducible

References

* bsc#1228182

* bsc#1228690

* bsc#1229079

* bsc#1229104

* bsc#1230361

* bsc#1231497

* bsc#1231568

* bsc#1231759

* bsc#1232575

* bsc#1232769

* bsc#1232817

* bsc#1233202

* bsc#1233279

* bsc#1233630

* bsc#1233660

* bsc#1233667

* bsc#1234123

* jsc#ECO-3319

* jsc#MSQA-914

Cross-

* CVE-2024-22037

CVSS scores:

* CVE-2024-22037 ( SUSE ): 5.7

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L

* CVE-2024-22037 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

* CVE-2024-22037 ( NVD ): 5.7

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2024-22037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Announcement ID: SUSE-SU-202501:15286-1
Release Date: 2025-02-14T07:19:29Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here