Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was affected by multiple vulnerabilities. CVE-2023-28486 Sudo did not escape control characters in log messages.. Debian LTS Advisory DLA-4472-1
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for resource-agents ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2336-1 Rating: moderate References: #1146691 Affected Products: SUSE Linux Enterprise High Availability 15-SP1 SUSE Linux Enterprise High Performance Computing 15-SP1 SUSE Linux Enterprise Server 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP1 SUSE Linux Enterprise Storage 6 SUSE Manager Proxy 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Server 4.0 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for resource-agents fixes the following issues: - Fixed predictable log file in /tmp in mariadb.in (bsc#1146691). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise High Availability 15-SP1: zypper in -t patch SUSE-SLE-Product-HA-15-SP1-2022-2336=1 Package List: - SUSE Linux Enterprise High Availability 15-SP1 (aarch64 ppc64le s390x x86_64): ldirectord-4.3.0184.6ee15eb2-150100.4.66.1 resource-agents-4.3.0184.6ee15eb2-150100.4.66.1 resource-agents-debuginfo-4.3.0184.6ee15eb2-150100.4.66.1 resource-agents-debugsource-4.3.0184.6ee15eb2-150100.4.66.1 - SUSE Linux Enterprise High Availability 15-SP1 (noarch): monitoring-plugins-metadata-4.3.0184.6ee15eb2-150100.4.66.1 References: https://bugzilla.suse.com/1146691 . SUSE Security Patch for resource-agents with medium severity tackling foreseeable loggingconcerns.. SUSE Linux Enterprise, Security Update, log issue, resource-agents, moderate severity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.