SUSE-SU-2016:1367-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1367-1
SUSE-SU-2016:1367-1
Summary: Security update for SUSE Manager Server 2.1
Details: This update for SUSE Manager Server 2.1 fixes the following issues: cobbler: - Add logrotate file for cobbler (bsc#976826) - Fix cobbler yaboot handling (bsc#968406, bsc#966622) osad: - Fix file permissions (bsc#970550) rhnlib: - Use TLSv1_METHOD in SSL Context (bsc#970989) spacewalk-backend: - Mgr_ncc_sync: Adapt to bulk scheduling introduced in scheduleSingleSatRepoSync spacewalk-branding: - Fix link to 'Schedule patch updates' (bsc#973432) - Fix link to scheduled action for SP migration (bsc#968257, bsc#974315) - Fix: 'Advanced Search' title consistency spacewalk-certs-tools: - Fix file permissions (bsc#970550) spacewalk-java: - Recreate upgrade paths on every refresh (bsc#978166) - Call cobbler sync after cobbler command is finished (bsc#966890) - Under high load, the service wrapper may incorrectly interpret the inability to get a response in time from taskomatic and kill it (bsc#962253) - Log permissions problems on channel access while SP migration (bsc#970223) - Unittests: support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194) - Mgr-sync: use bulk channel reposync (bsc#961002) - Double the backslashes when reading the config files from java (bsc#958923) - When generating repo metadata for a cloned channel, recursively fetch keywords from the original channel (bsc#970901) - Better logging for SP Migration feature (bsc#970223) - Fix: 'Advanced Search' title consistency - CVE-2015-0284: XSS when altering user details and going somewhere where you are choosing user (bsc#922740) - CVE-2016-3079, CVE-2016-2103, CVE-2016-2104, CVE-2016-3097: Fix multiple XSS vulnerabilities (bsc#973162, bsc#974011, bsc#974010, bsc#973550) - BugFix: 'Systems > Advanced Search' title and description consistency (bsc#966737) - Fix: correct behavior with visibility conditions of sub-tabs in Systems/Misc page - BugFix: add missing url mapping (bsc#961565) - Fix kernel and initrd pathes for creating autoinstallation tries (bsc#966622) - Fix tests for HAE-GEO on SLES 4 SAP (bsc#970425) - Add unit tests for SLE-Live-Patching12 (bsc#924298) spacewalk-utils: - Bugfix: don't repeat channel labels - Taskotop: a utility to monitor what Taskomatic is doing - Fix file permissions (bsc#970550) suseRegisterInfo: - Fix file permissions (bsc#970550) susemanager: - Add packages to bootstrap repo (bsc#971237) - Mgr-sync: use bulk channel reposync (bsc#961002) - Mgr_ncc_sync: adapt to bulk scheduling introduced in scheduleSingleSatRepoSync - Add SLES 4 SAP to mgr-create-bootstap-repo as an option (bsc#972341) - Put packages only available in SLE12 SP1 in a seperate list (bsc#970672) - Fix file permissions (bsc#970550) susemanager-sync-data: - Support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194) - HAE-GEO is an addon product for SLES 4 SAP (bsc#970425) - Add support for SLE-Live-Patching12 (bsc#924298, bsc#968851) susemanager-tftpsync: - Rename change_tftpd_proxies.py to sync_post_tftpd_proxies.py and change trigger type (bsc#966890) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: spacewalk-service start
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/, https://bugzilla.suse.com/922740, https://bugzilla.suse.com/924298, https://bugzilla.suse.com/958923, https://bugzilla.suse.com/961002, https://bugzilla.suse.com/961565, https://bugzilla.suse.com/962253, https://bugzilla.suse.com/966622, https://bugzilla.suse.com/966737, https://bugzilla.suse.com/966890, https://bugzilla.suse.com/968257, https://bugzilla.suse.com/968406, https://bugzilla.suse.com/968851, https://bugzilla.suse.com/970223, https://bugzilla.suse.com/970425, https://bugzilla.suse.com/970550, https://bugzilla.suse.com/970672, https://bugzilla.suse.com/970901, https://bugzilla.suse.com/970989, https://bugzilla.suse.com/971237, https://bugzilla.suse.com/972341, https://bugzilla.suse.com/973162, https://bugzilla.suse.com/973432, https://bugzilla.suse.com/973550, https://bugzilla.suse.com/974010, https://bugzilla.suse.com/974011, https://bugzilla.suse.com/974315, https://bugzilla.suse.com/976194, https://bugzilla.suse.com/976826, https://bugzilla.suse.com/978166, https://www.suse.com/security/cve/CVE-2015-0284, https://www.suse.com/security/cve/CVE-2016-2103, https://www.suse.com/security/cve/CVE-2016-2104, https://www.suse.com/security/cve/CVE-2016-3079, https://www.suse.com/security/cve/CVE-2016-3097
Affected packages
Package
Name: cobbler
Purl: pkg:rpm/suse/cobbler&distro=SUSE%20Manager%202.1
Affected ranges
Type: ECOSYSTEM
Events:
