SUSE-SU-2016:1346-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1346-1
SUSE-SU-2016:1346-1
Summary: Security update for systemd
Details: This update for SystemD provides fixes and enhancements. The following security issue has been fixed: - Don't allow read access to journal files to users. (bsc#972612, CVE-2014-9770, CVE-2015-8842) The following non-security issues have been fixed: - Restore initrd-udevadm-cleanup-db.service. (bsc#978275, bsc#976766) - Incorrect permissions set after boot on journal files. (bsc#973848) - Exclude device-mapper from block device ownership event locking. (bsc#972727) - Explicitly set mode for /run/log. - Don't apply sgid and executable bit to journal files, only the directories they are contained in. - Add ability to mask access mode by pre-existing access mode on files/directories. - No need to pass --all if inactive is explicitly requested in list-units. (bsc#967122) - Fix automount option and don't start associated mount unit at boot. (bsc#970423) - Support more than just power-gpio-key. (fate#318444, bsc#970860) - Add standard gpio power button support. (fate#318444, bsc#970860) - Downgrade warnings about wanted unit which are not found. (bsc#960158) - Shorten hostname before checking for trailing dot. (bsc#965897) - Remove WorkingDirectory parameter from emergency, rescue and console-shell.service. (bsc#959886) - Don't ship boot.udev and systemd-journald.init anymore. - Revert 'log: honour the kernel's quiet cmdline argument'. (bsc#963230)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161346-1/, https://bugzilla.suse.com/959886, https://bugzilla.suse.com/960158, https://bugzilla.suse.com/963230, https://bugzilla.suse.com/965897, https://bugzilla.suse.com/967122, https://bugzilla.suse.com/970423, https://bugzilla.suse.com/970860, https://bugzilla.suse.com/972612, https://bugzilla.suse.com/972727, https://bugzilla.suse.com/973848, https://bugzilla.suse.com/976766, https://bugzilla.suse.com/978275, https://www.suse.com/security/cve/CVE-2014-9770, https://www.suse.com/security/cve/CVE-2015-8842
Affected packages
Package
Name: systemd
Purl: pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
