SUSE-SU-2016:2627-1

    Dashboard / Vulnerabilities / SUSE-SU-2016:2627-1

    SUSE-SU-2016:2627-1

    Published: 25 Oct 2016Last Modified: 25 Oct 2016

    Summary: Security update for POS_Image3, POS_Server3

    Details: This update provides POS_Image3 and POS_Server3 version 3.5.5, which bring many fixes and enhancements: - Fixed potential security issues (bsc#946740) * use three argument perl open function consistently * use array in perl system call everywhere * use preferably perl built-in functions instead of external shell commands * improved validation of uploaded files from terminals to BS * improved runcmd code used for calling external commands - Auto-registration should not start before dhcpd is ready (bsc#1003383) - Fixed handling of HTTP redirects in registerImages (bsc#1003376) - Fixed handling x86_64 images (bsc#1003374) - Do not limit number of entries for BS LDAP (bsc#985979) - Increase max wait time to 10mins (bsc#989247) - Infer service IP when only one BS NIC is specified in LDAP (bsc#927232) - Fixed regression in directly referenced image in scWorkstation object (bsc#979925) - Fixed handling deltas of compressed images in registerImages (bsc#887607) - Fixed posleases to handle stop event correctly (bsc#883017) - Fixed save_poslogs utility to dump LDAP content on BS (bsc#890002) - Do not configure authoritative DNS outside netmask (bsc#889665) - Add ipHostNumber field to services in posAdmin-GUI (bsc#944292) - Fixed multival modification in posAdmin (bsc#840279)

    Affected packages

    Package

    Name: POS_Image3

    Purl: pkg:rpm/suse/POS_Image3&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.5.5-18.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2016:2627-1 | CVE-DB