SUSE-SU-2016:1367-1

    Dashboard / Vulnerabilities / SUSE-SU-2016:1367-1

    SUSE-SU-2016:1367-1

    Published: 19 May 2016Last Modified: 4 Feb 2026

    Summary: Security update for SUSE Manager Server 2.1

    Details: This update for SUSE Manager Server 2.1 fixes the following issues: cobbler: - Add logrotate file for cobbler (bsc#976826) - Fix cobbler yaboot handling (bsc#968406, bsc#966622) osad: - Fix file permissions (bsc#970550) rhnlib: - Use TLSv1_METHOD in SSL Context (bsc#970989) spacewalk-backend: - Mgr_ncc_sync: Adapt to bulk scheduling introduced in scheduleSingleSatRepoSync spacewalk-branding: - Fix link to 'Schedule patch updates' (bsc#973432) - Fix link to scheduled action for SP migration (bsc#968257, bsc#974315) - Fix: 'Advanced Search' title consistency spacewalk-certs-tools: - Fix file permissions (bsc#970550) spacewalk-java: - Recreate upgrade paths on every refresh (bsc#978166) - Call cobbler sync after cobbler command is finished (bsc#966890) - Under high load, the service wrapper may incorrectly interpret the inability to get a response in time from taskomatic and kill it (bsc#962253) - Log permissions problems on channel access while SP migration (bsc#970223) - Unittests: support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194) - Mgr-sync: use bulk channel reposync (bsc#961002) - Double the backslashes when reading the config files from java (bsc#958923) - When generating repo metadata for a cloned channel, recursively fetch keywords from the original channel (bsc#970901) - Better logging for SP Migration feature (bsc#970223) - Fix: 'Advanced Search' title consistency - CVE-2015-0284: XSS when altering user details and going somewhere where you are choosing user (bsc#922740) - CVE-2016-3079, CVE-2016-2103, CVE-2016-2104, CVE-2016-3097: Fix multiple XSS vulnerabilities (bsc#973162, bsc#974011, bsc#974010, bsc#973550) - BugFix: 'Systems > Advanced Search' title and description consistency (bsc#966737) - Fix: correct behavior with visibility conditions of sub-tabs in Systems/Misc page - BugFix: add missing url mapping (bsc#961565) - Fix kernel and initrd pathes for creating autoinstallation tries (bsc#966622) - Fix tests for HAE-GEO on SLES 4 SAP (bsc#970425) - Add unit tests for SLE-Live-Patching12 (bsc#924298) spacewalk-utils: - Bugfix: don't repeat channel labels - Taskotop: a utility to monitor what Taskomatic is doing - Fix file permissions (bsc#970550) suseRegisterInfo: - Fix file permissions (bsc#970550) susemanager: - Add packages to bootstrap repo (bsc#971237) - Mgr-sync: use bulk channel reposync (bsc#961002) - Mgr_ncc_sync: adapt to bulk scheduling introduced in scheduleSingleSatRepoSync - Add SLES 4 SAP to mgr-create-bootstap-repo as an option (bsc#972341) - Put packages only available in SLE12 SP1 in a seperate list (bsc#970672) - Fix file permissions (bsc#970550) susemanager-sync-data: - Support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194) - HAE-GEO is an addon product for SLES 4 SAP (bsc#970425) - Add support for SLE-Live-Patching12 (bsc#924298, bsc#968851) susemanager-tftpsync: - Rename change_tftpd_proxies.py to sync_post_tftpd_proxies.py and change trigger type (bsc#966890) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: spacewalk-service start

    Affected packages

    Package

    Name: cobbler

    Purl: pkg:rpm/suse/cobbler&distro=SUSE%20Manager%202.1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.2.2-0.61.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High