* bsc#1140749 Cross-References: * CVE-2019-13313 . # Security update for libosinfo Announcement ID: SUSE-SU-2024:1700-1 Rating: low References: * bsc#1140749 Cross-References: * CVE-2019-13313 CVSS scores: * CVE-2019-13313 ( SUSE ): 2.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N * CVE-2019-13313 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2019-13313 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libosinfo fixes the following issues: * CVE-2019-13313: Fixed password leak via command line argument inside osinfo- install-script (bsc#1140749). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1700=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1700=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1700=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1700=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libosinfo-debugsource-1.2.0-3.3.2 * libosinfo-debuginfo-1.2.0-3.3.2 * libosinfo-devel-1.2.0-3.3.2 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * typelib-1_0-Libosinfo-1_0-1.2.0-3.3.2 * libosinfo-debugsource-1.2.0-3.3.2 *libosinfo-1_0-0-1.2.0-3.3.2 * libosinfo-1.2.0-3.3.2 * libosinfo-debuginfo-1.2.0-3.3.2 * libosinfo-1_0-0-debuginfo-1.2.0-3.3.2 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * libosinfo-lang-1.2.0-3.3.2 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * typelib-1_0-Libosinfo-1_0-1.2.0-3.3.2 * libosinfo-debugsource-1.2.0-3.3.2 * libosinfo-1_0-0-1.2.0-3.3.2 * libosinfo-1.2.0-3.3.2 * libosinfo-debuginfo-1.2.0-3.3.2 * libosinfo-1_0-0-debuginfo-1.2.0-3.3.2 * SUSE Linux Enterprise Server 12 SP5 (noarch) * libosinfo-lang-1.2.0-3.3.2 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * typelib-1_0-Libosinfo-1_0-1.2.0-3.3.2 * libosinfo-debugsource-1.2.0-3.3.2 * libosinfo-1_0-0-1.2.0-3.3.2 * libosinfo-1.2.0-3.3.2 * libosinfo-debuginfo-1.2.0-3.3.2 * libosinfo-1_0-0-debuginfo-1.2.0-3.3.2 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * libosinfo-lang-1.2.0-3.3.2 ## References: * https://www.suse.com/security/cve/CVE-2019-13313.html * https://bugzilla.suse.com/show_bug.cgi?id=1140749 . This advisory highlights a vulnerability identified in libosinfo, offering guidance for remediation on impacted SUSE platforms.. libosinfo, security update, SUSE patches, threat management. . Severity: Low. LinuxSecurity.com Team
Updated libosinfo packages fix security vulnerability: A flaw was found in libosinfo, version 1.5.0, where the script for automated guest installations, 'osinfo-install-script', accepts user and admin passwords via command line arguments. This could allow guest . MGASA-2021-0325 - Updated libosinfo packages fix security vulnerability Publication date: 10 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0325.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13313 Updated libosinfo packages fix security vulnerability: A flaw was found in libosinfo, version 1.5.0, where the script for automated guest installations, 'osinfo-install-script', accepts user and admin passwords via command line arguments. This could allow guest passwords to leak to other system users via a process listing (CVE-2019-13313). The libosinfo package has been updated to version 1.8.0, fixing this issue and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=25112 - https://access.redhat.com/errata/RHSA-2019:3387 - https://access.redhat.com/errata/RHBA-2020:4758 - https://www.cve.org/CVERecord?id=CVE-2019-13313 SRPMS: - 7/core/libosinfo-1.8.0-1.mga7 . Revised libosinfo updates tackle critical security vulnerabilities to safeguard confidential credential information from illicit exposure.. libosinfo security update, Mageia libosinfo, command line vulnerability, security patch. . LinuxSecurity.com Team
Libosinfo: osinfo-install-script option leaks password via command line argument SL7 x86_64 libosinfo-1.1.0-5.el7.i686.rpm libosinfo-1.1.0-5.el7.x86_64.rpm libosinfo-debuginfo-1.1.0-5.el7.i686.rpm libosinfo-debuginfo-1.1.0-5.el7.x86_64.rpm libosinfo-devel-1.1.0-5.el7.i686.rpm libosinfo-devel-1.1.0-5.el7.x86_64.rpm libosinfo-vala-1.1.0-5.el7.x86_64.rpm - Scien [More...]. Synopsis: Low: libosinfo security and bug fix update Advisory ID: SLSA-2020:1051-1 Issue Date: 2020-04-07 CVE Numbers: CVE-2019-13313 -- * Libosinfo: osinfo-install-script option leaks password via command line argument -- SL7 x86_64 libosinfo-1.1.0-5.el7.i686.rpm libosinfo-1.1.0-5.el7.x86_64.rpm libosinfo-debuginfo-1.1.0-5.el7.i686.rpm libosinfo-debuginfo-1.1.0-5.el7.x86_64.rpm libosinfo-devel-1.1.0-5.el7.i686.rpm libosinfo-devel-1.1.0-5.el7.x86_64.rpm libosinfo-vala-1.1.0-5.el7.x86_64.rpm - Scientific Linux Development Team . Libosinfo patch resolves command line credential exposure vulnerabilities in SL7 x86_64. Significant advisory information provided.. libosinfo, security, password leak, scientific linux, update. . Severity: Low. LinuxSecurity.com Team
An update for osinfo-db, osinfo-db-tools, libosinfo, and gnome-boxes is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: osinfo-db and libosinfo security and bug fix update Advisory ID: RHSA-2019:3387-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3387 Issue date: 2019-11-05 CVE Names: CVE-2019-13313 ==================================================================== 1. Summary: An update for osinfo-db, osinfo-db-tools, libosinfo, and gnome-boxes is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The osinfo-db package contains a database that provides information about operating systems and hypervisor platforms to facilitate the automated configuration and provisioning of new virtual machines. The libosinfo packages provide a library that allows virtualization provisioning tools to determine the optimal device settings for a combination of hypervisor and operating system. Security Fix(es): * Libosinfo: osinfo-install-script option leaks password via command line argument (CVE-2019-13313) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in theReferences section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1685364 - Add win2019 to libosinfo 1689817 - virt-manager cannot detect operating system name for rhel8.0.0 tree automatically 1699988 - Rebase to the latest upstream release 1699989 - Rebase to the latest upstream release 1699990 - Rebase to the latest upstream release 1703480 - RHEL-8.0.x is not detected as RHEL-8.0 1713130 - gnome-boxes does not show RHEL-8 logo in Source Selection 1713245 - Add rhel-8.1 and rhel-7.7 entries 1727766 - CVE-2019-13313 Libosinfo: osinfo-install-script option leaks password via command line argument 1739897 - RHEL8.1 ppc64le iso is recognized as x86_64 by Boxes (Source Selection) 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: gnome-boxes-3.28.5-7.el8.src.rpm libosinfo-1.5.0-3.el8.src.rpm osinfo-db-20190611-1.el8.src.rpm osinfo-db-tools-1.5.0-4.el8.src.rpm aarch64: libosinfo-1.5.0-3.el8.aarch64.rpm libosinfo-debuginfo-1.5.0-3.el8.aarch64.rpm libosinfo-debugsource-1.5.0-3.el8.aarch64.rpm osinfo-db-tools-1.5.0-4.el8.aarch64.rpm osinfo-db-tools-debuginfo-1.5.0-4.el8.aarch64.rpm osinfo-db-tools-debugsource-1.5.0-4.el8.aarch64.rpm noarch: osinfo-db-20190611-1.el8.noarch.rpm ppc64le: libosinfo-1.5.0-3.el8.ppc64le.rpm libosinfo-debuginfo-1.5.0-3.el8.ppc64le.rpm libosinfo-debugsource-1.5.0-3.el8.ppc64le.rpm osinfo-db-tools-1.5.0-4.el8.ppc64le.rpm osinfo-db-tools-debuginfo-1.5.0-4.el8.ppc64le.rpm osinfo-db-tools-debugsource-1.5.0-4.el8.ppc64le.rpm s390x: libosinfo-1.5.0-3.el8.s390x.rpm libosinfo-debuginfo-1.5.0-3.el8.s390x.rpm libosinfo-debugsource-1.5.0-3.el8.s390x.rpm osinfo-db-tools-1.5.0-4.el8.s390x.rpm osinfo-db-tools-debuginfo-1.5.0-4.el8.s390x.rpm osinfo-db-tools-debugsource-1.5.0-4.el8.s390x.rpm x86_64: gnome-boxes-3.28.5-7.el8.x86_64.rpm gnome-boxes-debuginfo-3.28.5-7.el8.x86_64.rpm gnome-boxes-debugsource-3.28.5-7.el8.x86_64.rpm libosinfo-1.5.0-3.el8.i686.rpm libosinfo-1.5.0-3.el8.x86_64.rpm libosinfo-debuginfo-1.5.0-3.el8.i686.rpm libosinfo-debuginfo-1.5.0-3.el8.x86_64.rpm libosinfo-debugsource-1.5.0-3.el8.i686.rpm libosinfo-debugsource-1.5.0-3.el8.x86_64.rpm osinfo-db-tools-1.5.0-4.el8.x86_64.rpm osinfo-db-tools-debuginfo-1.5.0-4.el8.x86_64.rpm osinfo-db-tools-debugsource-1.5.0-4.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-13313 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/ 8. Contact: The Red Hat security contact is . Morecontact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPG v1 iQIVAwUBXcHq5dzjgjWX9erEAQh0hg/+P8wzRr250/uu08KTiidhlpGoW71J4H8n ASfwbAoZor9/8Y7ocyNtDMXoZjeSgXmuMyDeFxvD2oG1pWSJJWGM5jA3zkf1BFMj 9YpvBh5Gs/xN+9YQzxWFY/SOLKsBiGa12pok1zJxnMIkYJKyzg0XYforwctBPW2c Fn5pKUWGzZdvbDWv6UhtTr50A7Sq2Pp9AfGE98PSxwHTEZCb/aOQ+S/NnC/k2ruT fZfZlEaSxLxfDz6VRzOl/tIicoYHFR/wHAWJeatfG1PMbQE2jncTNcQueVseGwP7 q3GSTt5nPbMvdw44+AowuP5f+sGsgBerXW3YxhFvyW0xFgogfGxUOlOzTffyTkQP QeSgyGp87z7JIYg8y+ki8qrS8qOczLCD8ulV0ygD9/pGiZDYG5UR2Y+rY6sbDsHJ ViEpwIL5tnoYOySzGxR05z0TJr9rqKzxvGa/i1EhVSmOSms0eE497cWVXDHT/piY llxbU2pAY1kD6qTuThF1In5OtTmVLgESiehPfkhWceeDrt5s1J7BhQwDBzjzAwyX EBlkUGQQTd5QSMA1Kp5kVuOzcHnunJOzByJwJBYBVhUNL2L6MIYvvjuqYU1jkRcF /Tu/jqzGCtz7nwQa3zE3lO9z3QMUMDkLvXm4Jpu4wuSIh5qkALLYXM57R8rIeE+W NsJzc3JlgUc=2/Xj -----END PGP SIGNATURE-------RHSA-announce mailing list
An update that solves one vulnerability and has three fixes is now available. . SUSE Security Update: Security update for libosinfo ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2273-1 Rating: moderate References: #1054986 #1105607 #1122858 #1140749 Cross-References: CVE-2019-13313 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for libosinfo fixes the following issues: Security issue fixed: - CVE-2019-13313: Fixed a information leak where a local user could gather credentials from the osinfo-install-script (bsc#1140749). Non-security issues fixed: - Fixed OS detection for multiple versions of SLE12, SLE15 and openSUSE Leap (bsc#1105607, bsc#1122858, bsc#1105607, bsc#1054986, bsc#1054986) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-2273=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-2273=1 Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): libosinfo-0.2.12-13.3.1 libosinfo-1_0-0-0.2.12-13.3.1 libosinfo-1_0-0-debuginfo-0.2.12-13.3.1 libosinfo-debuginfo-0.2.12-13.3.1 libosinfo-debugsource-0.2.12-13.3.1 typelib-1_0-Libosinfo-1_0-0.2.12-13.3.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (noarch): libosinfo-lang-0.2.12-13.3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): libosinfo-0.2.12-13.3.1 libosinfo-1_0-0-0.2.12-13.3.1 libosinfo-1_0-0-debuginfo-0.2.12-13.3.1 libosinfo-debuginfo-0.2.12-13.3.1 libosinfo-debugsource-0.2.12-13.3.1 typelib-1_0-Libosinfo-1_0-0.2.12-13.3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): libosinfo-lang-0.2.12-13.3.1 References: https://www.suse.com/security/cve/CVE-2019-13313.html https://bugzilla.suse.com/1054986 https://bugzilla.suse.com/1105607 https://bugzilla.suse.com/1122858 https://bugzilla.suse.com/1140749 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.