SUSE-SU-2017:0475-1

    Dashboard / Vulnerabilities / SUSE-SU-2017:0475-1

    SUSE-SU-2017:0475-1

    Published: 16 Feb 2017Last Modified: 4 Feb 2026

    Summary: Security update for susestudio

    Details: This update provides SUSE Studio Runner 1.3.14, which brings fixes for the following issues: - bsc#968797: 11 SP3 appliance gets invalid distribution upgrade from SLMS. - bsc#947225: Second build of appliance will not register to SLMS, wrong product name. - bsc#983404: UEFI boot missing for SLE11 SP4. - bsc#972406: Kiwi export config.sh script has /build-custom out of order. - bsc#981095: Add user 'ldap' to default_users list for assigning owners for overlay files. - bsc#972425: Runlevel 3 is being ignored in appliance configuration. - bsc#983999: SLES 12 appliance build does not include gpg keys from base product. - bsc#979110: SLES 12 will not build for EC2. - bsc#929102: Plaintext Password Local Disclosure in rubygem-rest-client. (CVE-2015-3448) - bsc#963741: Security fixes for Rails v3.2.22. (CVE-2015-7576, CVE-2015-7577, CVE-2016-0751, CVE-2016-0752)

    Affected packages

    Package

    Name: libjansson

    Purl: pkg:rpm/suse/libjansson&distro=SUSE%20Studio%20Onsite%201.3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.2.1-0.9.11.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2017:0475-1 | CVE-DB