Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openslp ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1917-1 Rating: important References: #1090638 Cross-References: CVE-2017-17833 Affected Products: SUSE Linux Enterprise Module for Server Applications 15 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openslp fixes the following issues: - CVE-2017-17833: Prevent heap-related memory corruption issue which may have manifested itself as a denial-of-service or a remote code-execution vulnerability (bsc#1090638) - Prevent out of bounds reads in message parsing Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-2018-1292=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1292=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15 (aarch64 ppc64le s390x x86_64): openslp-debuginfo-2.0.0-6.3.1 openslp-debugsource-2.0.0-6.3.1 openslp-server-2.0.0-6.3.1 openslp-server-debuginfo-2.0.0-6.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): openslp-2.0.0-6.3.1 openslp-debuginfo-2.0.0-6.3.1 openslp-debugsource-2.0.0-6.3.1 openslp-devel-2.0.0-6.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (x86_64): openslp-32bit-2.0.0-6.3.1 openslp-32bit-debuginfo-2.0.0-6.3.1 References: https://www.suse.com/security/cve/CVE-2017-17833.html https://bugzilla.suse.com/1090638 . SUSE Security Patch for openssl addresses vulnerabilities causing system instability and memory leaks. Ensure your systems are protected with current updates.. SUSE Security Update, openslp Patch, Linux Enterprise Module, memory corruption fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.