yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL6 noarch yum-plugin-aliases-1.1.30-42.el6_10.noarch.rpm yum-plugin-changelog-1.1.30-42.el6_10.noarch.rpm yum-plugin-ovl-1.1.30-42.el6_10.noarch.rpm yum-plugin-security-1.1.30-42.el6_10.noarch.rpm yum-plugin-tmprepo-1.1.30-42.el6_10.noarch.rpm yum-plugin-verify-1.1.30-42.e [More...]. Synopsis: Important: yum-utils security update Advisory ID: SLSA-2018:2284-1 Issue Date: 2018-07-30 CVE Numbers: CVE-2018-10897 -- Security Fix(es): * yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) -- SL6 noarch yum-plugin-aliases-1.1.30-42.el6_10.noarch.rpm yum-plugin-changelog-1.1.30-42.el6_10.noarch.rpm yum-plugin-ovl-1.1.30-42.el6_10.noarch.rpm yum-plugin-security-1.1.30-42.el6_10.noarch.rpm yum-plugin-tmprepo-1.1.30-42.el6_10.noarch.rpm yum-plugin-verify-1.1.30-42.el6_10.noarch.rpm yum-plugin-versionlock-1.1.30-42.el6_10.noarch.rpm yum-utils-1.1.30-42.el6_10.noarch.rpm yum-NetworkManager-dispatcher-1.1.30-42.el6_10.noarch.rpm yum-plugin-auto-update-debug-info-1.1.30-42.el6_10.noarch.rpm yum-plugin-fastestmirror-1.1.30-42.el6_10.noarch.rpm yum-plugin-filter-data-1.1.30-42.el6_10.noarch.rpm yum-plugin-fs-snapshot-1.1.30-42.el6_10.noarch.rpm yum-plugin-keys-1.1.30-42.el6_10.noarch.rpm yum-plugin-list-data-1.1.30-42.el6_10.noarch.rpm yum-plugin-local-1.1.30-42.el6_10.noarch.rpm yum-plugin-merge-conf-1.1.30-42.el6_10.noarch.rpm yum-plugin-post-transaction-actions-1.1.30-42.el6_10.noarch.rpm yum-plugin-priorities-1.1.30-42.el6_10.noarch.rpm yum-plugin-protectbase-1.1.30-42.el6_10.noarch.rpm yum-plugin-ps-1.1.30-42.el6_10.noarch.rpm yum-plugin-remove-with-leaves-1.1.30-42.el6_10.noarch.rpm yum-plugin-rpm-warm-cache-1.1.30-42.el6_10.noarch.rpm yum-plugin-show-leaves-1.1.30-42.el6_10.noarch.rpm yum-plugin-tsflags-1.1.30-42.el6_10.noarch.rpm yum-plugin-upgrade-helper-1.1.30-42.el6_10.noarch.rpm yum-updateonboot-1.1.30-42.el6_10.noarch.rpm - Scientific Linux Development Team . Critical advisory issued for yum-utils mitigating directory traversal vulnerability on Scientific Linux version.. yum-utils,yum-plugin,security patch,directory traversal,yum-reposync. . Severity: Important. LinuxSecurity.com Team
yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL7 noarch yum-plugin-aliases-1.1.31-46.el7_5.noarch.rpm yum-plugin-changelog-1.1.31-46.el7_5.noarch.rpm yum-plugin-ovl-1.1.31-46.el7_5.noarch.rpm yum-plugin-tmprepo-1.1.31-46.el7_5.noarch.rpm yum-plugin-verify-1.1.31-46.el7_5.noarch.rpm yum-plugin-versionlock-1.1.31-46.el7 [More...]. Synopsis: Important: yum-utils security update Advisory ID: SLSA-2018:2285-1 Issue Date: 2018-07-30 CVE Numbers: CVE-2018-10897 -- Security Fix(es): * yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) -- SL7 noarch yum-plugin-aliases-1.1.31-46.el7_5.noarch.rpm yum-plugin-changelog-1.1.31-46.el7_5.noarch.rpm yum-plugin-ovl-1.1.31-46.el7_5.noarch.rpm yum-plugin-tmprepo-1.1.31-46.el7_5.noarch.rpm yum-plugin-verify-1.1.31-46.el7_5.noarch.rpm yum-plugin-versionlock-1.1.31-46.el7_5.noarch.rpm yum-utils-1.1.31-46.el7_5.noarch.rpm yum-NetworkManager-dispatcher-1.1.31-46.el7_5.noarch.rpm yum-plugin-auto-update-debug-info-1.1.31-46.el7_5.noarch.rpm yum-plugin-copr-1.1.31-46.el7_5.noarch.rpm yum-plugin-fastestmirror-1.1.31-46.el7_5.noarch.rpm yum-plugin-filter-data-1.1.31-46.el7_5.noarch.rpm yum-plugin-fs-snapshot-1.1.31-46.el7_5.noarch.rpm yum-plugin-keys-1.1.31-46.el7_5.noarch.rpm yum-plugin-list-data-1.1.31-46.el7_5.noarch.rpm yum-plugin-local-1.1.31-46.el7_5.noarch.rpm yum-plugin-merge-conf-1.1.31-46.el7_5.noarch.rpm yum-plugin-post-transaction-actions-1.1.31-46.el7_5.noarch.rpm yum-plugin-pre-transaction-actions-1.1.31-46.el7_5.noarch.rpm yum-plugin-priorities-1.1.31-46.el7_5.noarch.rpm yum-plugin-protectbase-1.1.31-46.el7_5.noarch.rpm yum-plugin-ps-1.1.31-46.el7_5.noarch.rpm yum-plugin-remove-with-leaves-1.1.31-46.el7_5.noarch.rpm yum-plugin-rpm-warm-cache-1.1.31-46.el7_5.noarch.rpm yum-plugin-show-leaves-1.1.31-46.el7_5.noarch.rpm yum-plugin-tsflags-1.1.31-46.el7_5.noarch.rpm yum-plugin-upgrade-helper-1.1.31-46.el7_5.noarch.rpm yum-updateonboot-1.1.31-46.el7_5.noarch.rpm yum-utils-1.1.31-46.el7_5.src.rpm - Scientific Linux Development Team . Urgent yum-utils safety notice for Scientific Linux SL7 addressing CVE-2018-10897 concerning directory traversal vulnerabilities.. yum-utils,YUM Update,Security Advisory,Directory Traversal. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for cobbler ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1741-1 Rating: moderate References: #1074594 #1090205 Cross-References: CVE-2017-1000469 Affected Products: SUSE Linux Enterprise Server 11-SP4-CLIENT-TOOLS SUSE Linux Enterprise Server 11-SP3-CLIENT-TOOLS ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for cobbler fixes the following issues: - CVE-2017-1000469: Escape shell parameters provided by the user for the reposync action. (bsc#1074594) - Fix for calling koan with virt_type kvm. (bsc#1090205) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-CLIENT-TOOLS: zypper in -t patch slesctsp4-cobbler-13659=1 - SUSE Linux Enterprise Server 11-SP3-CLIENT-TOOLS: zypper in -t patch slesctsp3-cobbler-13659=1 Package List: - SUSE Linux Enterprise Server 11-SP4-CLIENT-TOOLS (i586 ia64 ppc64 s390x x86_64): koan-2.2.2-0.68.3.1 - SUSE Linux Enterprise Server 11-SP3-CLIENT-TOOLS (i586 ia64 ppc64 s390x x86_64): koan-2.2.2-0.68.3.1 References: https://www.suse.com/security/cve/CVE-2017-1000469.html https://bugzilla.suse.com/1074594 https://bugzilla.suse.com/1090205 . SUSE has released a Security Update to tackle a moderate vulnerability in cobbler, which contains critical fixes alongside clear installation guidelines.. SUSE Linux, Security Update, Cobber Security, Shell Escape. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.