An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for slurm ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3497-1 Rating: important References: #1199278 #1199279 #1201674 Cross-References: CVE-2022-29500 CVE-2022-29501 CVE-2022-31251 CVSS scores: CVE-2022-29500 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-29500 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-29501 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-29501 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-31251 (NVD) : 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Module for HPC 12 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for slurm fixes the following issues: - CVE-2022-31251: Fixed a potential security vulnerability in the test package (bsc#1201674). - CVE-2022-29500: Fixed architectural flaw that could have been exploited to allow an unprivileged user to execute arbitrary processes as root (bsc#1199278). - CVE-2022-29501: Fixed a problem that an unprivileged user could have sent data to arbitrary unix socket as root (bsc#1199279). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for HPC 12: zypper in -t patch SUSE-SLE-Module-HPC-12-2022-3497=1 Package List: - SUSE Linux Enterprise Module for HPC 12 (aarch64 x86_64): libpmi0-17.02.11-6.53.1 libpmi0-debuginfo-17.02.11-6.53.1 libslurm31-17.02.11-6.53.1 libslurm31-debuginfo-17.02.11-6.53.1 perl-slurm-17.02.11-6.53.1 perl-slurm-debuginfo-17.02.11-6.53.1 slurm-17.02.11-6.53.1 slurm-auth-none-17.02.11-6.53.1 slurm-auth-none-debuginfo-17.02.11-6.53.1 slurm-config-17.02.11-6.53.1 slurm-debuginfo-17.02.11-6.53.1 slurm-debugsource-17.02.11-6.53.1 slurm-devel-17.02.11-6.53.1 slurm-doc-17.02.11-6.53.1 slurm-lua-17.02.11-6.53.1 slurm-lua-debuginfo-17.02.11-6.53.1 slurm-munge-17.02.11-6.53.1 slurm-munge-debuginfo-17.02.11-6.53.1 slurm-pam_slurm-17.02.11-6.53.1 slurm-pam_slurm-debuginfo-17.02.11-6.53.1 slurm-plugins-17.02.11-6.53.1 slurm-plugins-debuginfo-17.02.11-6.53.1 slurm-sched-wiki-17.02.11-6.53.1 slurm-slurmdb-direct-17.02.11-6.53.1 slurm-slurmdbd-17.02.11-6.53.1 slurm-slurmdbd-debuginfo-17.02.11-6.53.1 slurm-sql-17.02.11-6.53.1 slurm-sql-debuginfo-17.02.11-6.53.1 slurm-torque-17.02.11-6.53.1 slurm-torque-debuginfo-17.02.11-6.53.1 References: https://www.suse.com/security/cve/CVE-2022-29500.html https://www.suse.com/security/cve/CVE-2022-29501.html https://www.suse.com/security/cve/CVE-2022-31251.html https://bugzilla.suse.com/1199278 https://bugzilla.suse.com/1199279 https://bugzilla.suse.com/1201674 . SUSE Security Patch for slurm (SUSE-SU-2022:3497-1) addresses severe execution errors and socket weaknesses.. SUSE Linux Security, Slurm Update, Critical Patch. . Severity: Important. LinuxSecurity.com Team
An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Enterprise Application Platform 5.2 security update Advisory ID: RHSA-2017:3400-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2017:3400 Issue date: 2017-12-07 CVE Names: CVE-2017-5645 ==================================================================== 1. Summary: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server. This asynchronous patch is a security update for log4j package in Red Hat JBoss Enterprise Application Platform 5.2.0. Security Fix(es): * It was found that when using remote logging with log4j socket server the log4j server would deserialize any log event received via TCP or UDP. An attacker could use this flaw to send a specially crafted log event that, during deserialization, would execute arbitrary code in the context of the logger application. (CVE-2017-5645) 3. Solution: Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed(https://bugzilla.redhat.com/): 1443635 - CVE-2017-5645 log4j: Socket receiver deserialization vulnerability 5. References: https://access.redhat.com/security/cve/CVE-2017-5645 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=5.2.0 https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/ 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFaKXSlXlSAg2UNWIIRArefAKCNrcHUuB0Jmu28+K8TfkCsg/WyQwCfXkmC tx/xABNMq0u6tyetMVwS2Kw=FsJF -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.