SUSE-SU-2017:2257-1

    Dashboard / Vulnerabilities / SUSE-SU-2017:2257-1

    SUSE-SU-2017:2257-1

    Published: 25 Aug 2017Last Modified: 4 Feb 2026

    Summary: Security update for SUSE Manager Server 3.1

    Details: This update for the SUSE Manager Server 3.1 provides several fixes and improvements. The following security issues have been fixed: jabberd: - Fix offered SASL mechanism check. (bsc#1047282, CVE-2017-10807) spacewalk-java: - Do not allow XSS as Organization name. (bsc#1048968, CVE-2017-7538) Additionally, the following non-security issues have been fixed: cobbler: - Fix missing arguments and location for Xen. (bsc#1048183) jabberd: - Fix memory leak in pgsql storage driver. - Fix two double-frees caused by dangling pointers. - wss:// (WebSocket over SSL) support in c2s. - Allow BareJID S10N packets. - SQLite postconnect SQL support. - Support WebSocket fragmented packets. - Module to verify users using e-mail. - Use OpenSSL functions for base64 en/decoding when available. - Option to dump packet-filter matched packets to file. - bcrypt support for PostgreSQL and MySQL storage. - Option to set authreg module per realm. - WebSocket C2S SX plugin. - Support for RSA/DH/ECDH key agreement. - For a detailed description of all fixes, please refer to the changelog. osad: - Reduce maximal size of osad log before rotating. - Perform osad restart in posttrans. (bsc#1039913) salt-netapi-client: - Fix date format for Schedule. - Fix sending kwarg in payload in RunnerCall. - Better error handling in Runner and Wheel calls. - Increase the default SOCKET_TIMEOUT to 20 seconds. smdba: - Add support for postgresql96. (bsc#1045152) spacecmd: - Configchannel export binary flag to json. (bsc#1044719) spacewalk-backend: - Make master_label static to keep its value when retrying. (bsc#1038321) - Adapt for the new gpgcheck flag for the channels. spacewalk-branding: - Fix overlapping of elements. (bsc#1031143) - Fix overlapping text narrow window. (bsc#1009118) - Fix formulas action buttons position. (bsc#1047513) - Fix broken link. (bsc#1033999) - Alphabar: Change title to 'Select first character'. (bsc#1042199) spacewalk-certs-tools: - Improve text for bootstrap. (bsc#1032324) spacewalk-java: - Don't add default channel if AK is not valid. (bsc#1047656) - Add 'Enable GPG check' function for channels. - No legend icon for Activity Ocurring. (bsc#1051719) - Implement API call for bootstrapping systems. - Fix product ids reported for SUSE Manager Server to the subscription matcher. - Fix adding products when assigning channels. (bsc#1049664) - Set default memory size for SLES 12 installations to 1024MB. (bsc#1047707) - Enable remote-command for Salt clients in SSM. (bsc#1050385) - Add missing help icons/links. (bsc#1049425) - Fix invalid help links. (bsc#1049425) - Fix wrong openscap xid. (bsc#1030898) - Fix overlapping text narrow window. (bsc#1009118) - Fixes alignment on the orgdetails. (bsc#1017513) - Fix text for activation key buttons. (bsc#1042975) - Correctly set, check and cut textarea maxlength. (bsc#1043430) - MinionActionExecutor: Raise skip timeout. (bsc#1046865) - Update channels.xml with OpenStack Cloud Continuous Delivery 6. (bsc#1039458) - Do not create VirtualInstance duplicates for the same 'uuid'. - Add taskomatic task to cleanup duplicated uuids for same system id. - Handle possible wrong UUIDs on SLE11 minions. (bsc#1046218) - Removed duplicate overview menu item. (bsc#1045981) - Enable act-key name empty on creation. (bsc#1032350) - Fix NPE when there's not udev results. (bsc#1042552) - Alphabar: Change title to 'Select first character'. (bsc#1042199) - Duplicate Systems: Correct language not to mention 'profiles'. (bsc#1035728) - Fix list filters to work with URL special characters. (bsc#1042846) - Use getActive() instead of isActive() for JavaBeans compliance. (bsc#1043143) - Fix hide non-org event details. (bsc#1039579) spacewalk-search: - Remove executable bit from service files. (bsc#1051518) spacewalk-utils: - Don't show password on input in spacewalk-manage-channel-lifecycle. (bsc#1043795) spacewalk-web: - Fix overlapping of elements. (bsc#1031143) - Fix formulas action buttons position. (bsc#1047513) - Do not show old messages. (bsc#1043831) - Add a dynamic counter of the remaining textarea length. - Confirm if navigating away while bootstrapping. susemanager: - Assert correct java version. (bsc#1049575) - Create bootstrap repository for SLES for SAP 11 SP1. (bsc#1049471) - Adjust the bootstrap repository with SLE 12 SP3 repositories. susemanager-docs_en: - Improve Icinga services example. (bsc#1019759) - Make Section reference Configuration Management more clear. (bsc#1047352) - Add missing 'host_name' in service definition example for Icinga. (bsc#1049162) - Fix documentation on moving database. (bsc#1031602) - Add missing Autoinstallation page in Advanced Topics guide. (bsc#1047680) - Make API documentation available online. (bsc#1047641) - Fix Reference Guide Documentation issues. (bsc#1045266) - Update online documentation components. (bsc#1046314) - Update online documentation. (bsc#1046176) susemanager-schema: - Adapt for the new gpgcheck flag for the channels. susemanager-sync-data: - Add support for SLE 12 SP3 product family, SUSE Enterprise Storage 5, OpenStack Cloud 6 Continuous Delivery and Public Cloud for ppc64le. (bsc#1028098, bsc#1039458, bsc#1037609, bsc#1049665) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start

    References: https://www.suse.com/support/update/announcement/2017/suse-su-20172257-1/, https://bugzilla.suse.com/1009118, https://bugzilla.suse.com/1017513, https://bugzilla.suse.com/1019759, https://bugzilla.suse.com/1028098, https://bugzilla.suse.com/1030898, https://bugzilla.suse.com/1031143, https://bugzilla.suse.com/1031602, https://bugzilla.suse.com/1032324, https://bugzilla.suse.com/1032350, https://bugzilla.suse.com/1033999, https://bugzilla.suse.com/1035728, https://bugzilla.suse.com/1037609, https://bugzilla.suse.com/1038321, https://bugzilla.suse.com/1039458, https://bugzilla.suse.com/1039579, https://bugzilla.suse.com/1039913, https://bugzilla.suse.com/1042199, https://bugzilla.suse.com/1042552, https://bugzilla.suse.com/1042846, https://bugzilla.suse.com/1042975, https://bugzilla.suse.com/1043143, https://bugzilla.suse.com/1043430, https://bugzilla.suse.com/1043795, https://bugzilla.suse.com/1043831, https://bugzilla.suse.com/1044719, https://bugzilla.suse.com/1045152, https://bugzilla.suse.com/1045266, https://bugzilla.suse.com/1045981, https://bugzilla.suse.com/1046176, https://bugzilla.suse.com/1046218, https://bugzilla.suse.com/1046314, https://bugzilla.suse.com/1046865, https://bugzilla.suse.com/1047282, https://bugzilla.suse.com/1047352, https://bugzilla.suse.com/1047513, https://bugzilla.suse.com/1047641, https://bugzilla.suse.com/1047656, https://bugzilla.suse.com/1047680, https://bugzilla.suse.com/1047707, https://bugzilla.suse.com/1048183, https://bugzilla.suse.com/1048968, https://bugzilla.suse.com/1049162, https://bugzilla.suse.com/1049425, https://bugzilla.suse.com/1049471, https://bugzilla.suse.com/1049575, https://bugzilla.suse.com/1049664, https://bugzilla.suse.com/1049665, https://bugzilla.suse.com/1050385, https://bugzilla.suse.com/1051518, https://bugzilla.suse.com/1051719, https://www.suse.com/security/cve/CVE-2017-10807, https://www.suse.com/security/cve/CVE-2017-7538

    Affected packages

    Package

    Name: cobbler

    Purl: pkg:rpm/suse/cobbler&distro=SUSE%20Manager%20Server%203.1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.6.6-5.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High