SUSE-SU-2016:2143-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2143-1
SUSE-SU-2016:2143-1
Summary: Security update for several openstack-components
Details: This update provides the latest code from OpenStack Liberty for openstack-ceilometer, -cinder, -dashboard, -glance, -heat, -keystone, -manila, -neutron, -neutron-fwaas, -neutron-lbaas,-nova, -resource-agents, python-networking-cisco and python-openstackclient. Additionally some security-issues have been fixed: openstack-nova: - Always copy or recreate disk.info during a migration. (bsc#970258, CVE-2016-2140) openstack-dashboard: - Escape anularjs templating in unsafe HTML. (bsc#983807, CVE-2016-4428) openstack-neutron: - Fix bypassing of anti-spoof protection. (bsc#984443, CVE-2016-5363, bsc#984442, CVE-2016-5362) For a detailed description of all fixes and improvements, please refer to the changelog.
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162143-1/, https://bugzilla.suse.com/970258, https://bugzilla.suse.com/982426, https://bugzilla.suse.com/983807, https://bugzilla.suse.com/984442, https://bugzilla.suse.com/984443, https://bugzilla.suse.com/988729, https://www.suse.com/security/cve/CVE-2016-2140, https://www.suse.com/security/cve/CVE-2016-4428, https://www.suse.com/security/cve/CVE-2016-5362, https://www.suse.com/security/cve/CVE-2016-5363
Affected packages
Package
Name: openstack-ceilometer
Purl: pkg:rpm/suse/openstack-ceilometer&distro=SUSE%20OpenStack%20Cloud%206
Affected ranges
Type: ECOSYSTEM
Events:
