An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for mailman ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1886-1 Rating: important References: #1191959 #1192735 #1192741 #1193316 Cross-References: CVE-2021-42096 CVE-2021-43331 CVE-2021-43332 CVE-2021-44227 CVSS scores: CVE-2021-42096 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-43331 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L CVE-2021-43332 (SUSE): 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L CVE-2021-44227 (SUSE): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L Affected Products: HPE Helion Openstack 8 SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for mailman fixes the following issues: - CVE-2021-44227: Preventing list moderator or list member accessing the admin UI (bsc#1193316). - CVE-2021-43332: Preventing list moderator from cracking the list admin password encrypted in a CSRF token (bsc#1192741). - CVE-2021-43331: Fixed XSS in Cgi/options.py (bsc#1192735). - CVE-2021-42096: Add protection against remoteprivilege escalation via csrf_token derived from admin password (bsc#1191959). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-1886=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-1886=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-1886=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-1886=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2022-1886=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2022-1886=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-1886=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2022-1886=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2022-1886=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-1886=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-1886=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-1886=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE OpenStack Cloud 9 (x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSEOpenStack Cloud 8 (x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (ppc64le s390x x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le s390x x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 - HPE Helion Openstack 8 (x86_64): mailman-2.1.17-3.26.1 mailman-debuginfo-2.1.17-3.26.1 mailman-debugsource-2.1.17-3.26.1 References: https://www.suse.com/security/cve/CVE-2021-42096.html https://www.suse.com/security/cve/CVE-2021-43331.html https://www.suse.com/security/cve/CVE-2021-43332.html https://www.suse.com/security/cve/CVE-2021-44227.html https://bugzilla.suse.com/1191959 https://bugzilla.suse.com/1192735 https://bugzilla.suse.com/1192741 https://bugzilla.suse.com/1193316 . Mailman update released to address critical issues in multiple SUSE products, improving security and access controls.. SUSE Mailman Update, Security Patches,Linux Updates. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP. CVE-2018-4056 . Package : coturn Version : 4.2.1.2-1+deb8u1 CVE ID : CVE-2018-4056 CVE-2018-4058 CVE-2018-4059 Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP. CVE-2018-4056 An SQL injection vulnerability was discovered in the coTURN administrator web portal. As the administration web interface is shared with the production, it is unfortunately not possible to easily filter outside access and this security update completely disables the web interface. Users should use the local, command line interface instead. CVE-2018-4058 Default configuration enables unsafe loopback forwarding. A remote attacker with access to the TURN interface can use this vulnerability to gain access to services that should be local only. CVE-2018-4059 Default configuration uses an empty password for the local command line administration interface. An attacker with access to the local console (either a local attacker or a remote attacker taking advantage of CVE-2018-4058) could escalade privileges to administrator of the coTURN server. For Debian 8 "Jessie", these problems have been fixed in version 4.2.1.2-1+deb8u1. We recommend that you upgrade your coturn packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Important coturn patch for Debian 8 addresses several security flaws improving overall protection. Upgrade suggested.. coturn security,debian updates,TURN server vulnerabilities,command line administration. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.