SUSE-SU-2018:0285-1

    Dashboard / Vulnerabilities / SUSE-SU-2018:0285-1

    SUSE-SU-2018:0285-1

    Published: 30 Jan 2018Last Modified: 4 Feb 2026

    Summary: Security update for SUSE Manager Server 3.0

    Details: This update fixes the following issues: !!!NOTE: For PostgreSQL, schema migrations could take a long time (hours), depending on the number of synced !!! !!!packages and number of rows which requires cleanup. Please refer to the release notes for more information.!!! nutch: - Fix log hadoop into proper directory. (bsc#1061574) osad: - Fixed TypeError for force flag in setup_config that could happen when jabberd restart was needed. (bsc#1064393) pxe-default-image: - Spectre and Meltdown mitigation. (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754, bsc#1068032) spacecmd: - Added custom JSON encoder in order to parse date fields correctly. (bsc#1070372) spacewalk-backend: - Fix restore hostname and ip*addr in templated documents. (bsc#1075044) - Fix directory name in spacewalk-data-fsck. - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-branding: - Fix message about package profile synchronization. (bsc#1073739) - Fix naming of the Tools channel. (bsc#979633) spacewalk-client-tools: - Fix package sources. spacewalk-java: - Fix message about package profile synchronization. (bsc#1073739) - Add VM state as info gathered from VMware. (bsc#1063759) - Improve performance of token checking, when RPMs or metadata are downloaded from minions. (bsc#1061273) - Fix action names and date formatting in system event history. (bsc#1073713) - Fix incorrect 'os-release' report after SP migration. (bsc#1071553) - Fix failed package installation when in RES 32 and 64 bit packages are installed together. (bsc#1071314) - Add user preferences in order to change items-per-page. (bsc#1055296) - Display messages about wrong input more end-user friendly. (bsc#1015956) - Fix content refresh when product keys change. (bsc#1069943) - Allow 'Package List Refresh' when package architecture has changed. (bsc#1065259) - Support Open Enterprise Server 2018. (bsc#1060182) - Do not remove virtual instances for registered systems. (bsc#1063759) - Process right configfile on 'scheduleFileComparisons' API calls. (bsc#1066663) - Fix reported UUIDs for guests instances within a virtual host. (bsc#1063759) - Generate Order Items for OEM subscriptions. (bsc#1045141) - Enable 'Power Management' features on Salt minions. - Fail gracefully when GPG files are requested. (bsc#1065676) - Improve messaging for 'Compare Packages'. (bsc#1065844) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) spacewalk-reports: - More rhnServerNetwork refactoring. (bsc#1063419) spacewalk-search: - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-web: - Add user preferences in order to change items-per-page. (bsc#1055296) susemanager: - Support Open Enterprise Server 2018. (bsc#1060182) - Fixed bootstrap repository path for SLES4SAP version 12 and 12.1. (bsc#1062936) - Fix error message for database upgrade failure. - Check for sufficient diskspace in /var/lib/pgsql. - Notify admin that database backups need reconfiguration after db upgrade. susemanager-docs_en: - Update text and image files: - List Open Enterprise Server 2015, 2015 SP1, 2018 as supported clients. susemanager-schema: - Fix hostname schema upgrade. (bsc#1076622) - Fix duplicate entries in channel listings. - Handle nevra not found case while fixing duplicate evr ids. (bsc#1074508) - Enable 'Power Management' features on Salt minions. - Fix unique index for evr and capability and remove duplicates during migration. (bsc#1058110) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) susemanager-sls: - Python3 compatibility fixes in modules and states. - Fix failing certs state for Tumbleweed. (bsc#970630) - Fix deprecated SLS files to avoid deprecation warnings during highstate. (bsc#1041993) susemanager-sync-data: - Support Open Enterprise Server 2018. (bsc#1060182) - Fix description for HA channel. (bsc#1063588) - Add support for CAASP. (bsc#1052283) - Add IBM DLPAR channels to SLES for SAP SPx ppc64le. (bsc#1068057) - Remove Certification Module 12 from SP2 and SP3. (bsc#1066819) - Add SUSE Manager Server 3.0 and 3.1 channels for mirroring. - Support SLE-RT 12 SP3. (bsc#1063940) - Add SLE12 LTSS as extension to SLES for SAP 12. (bsc#1069615) - Remove OES2018 Debuginfo channels. (bsc#1071367) virtual-host-gatherer: - Add VM state as info gathered from VMware. (bsc#1063759) - Explore the entire tree of nodes from VMware. (bsc#1070597) - Skip safely VMs which have no config attribute on VMware. (bsc#1066923) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start

    References: https://www.suse.com/support/update/announcement/2018/suse-su-20180285-1/, https://bugzilla.suse.com/1015956, https://bugzilla.suse.com/1041993, https://bugzilla.suse.com/1045141, https://bugzilla.suse.com/1052283, https://bugzilla.suse.com/1055296, https://bugzilla.suse.com/1058110, https://bugzilla.suse.com/1060182, https://bugzilla.suse.com/1061273, https://bugzilla.suse.com/1061574, https://bugzilla.suse.com/1062936, https://bugzilla.suse.com/1063419, https://bugzilla.suse.com/1063588, https://bugzilla.suse.com/1063759, https://bugzilla.suse.com/1063891, https://bugzilla.suse.com/1063940, https://bugzilla.suse.com/1064393, https://bugzilla.suse.com/1065259, https://bugzilla.suse.com/1065676, https://bugzilla.suse.com/1065844, https://bugzilla.suse.com/1066404, https://bugzilla.suse.com/1066663, https://bugzilla.suse.com/1066819, https://bugzilla.suse.com/1066923, https://bugzilla.suse.com/1068032, https://bugzilla.suse.com/1068057, https://bugzilla.suse.com/1069615, https://bugzilla.suse.com/1069943, https://bugzilla.suse.com/1070372, https://bugzilla.suse.com/1070597, https://bugzilla.suse.com/1071314, https://bugzilla.suse.com/1071367, https://bugzilla.suse.com/1071553, https://bugzilla.suse.com/1073713, https://bugzilla.suse.com/1073739, https://bugzilla.suse.com/1074508, https://bugzilla.suse.com/1075044, https://bugzilla.suse.com/1076622, https://bugzilla.suse.com/970630, https://bugzilla.suse.com/979633, https://www.suse.com/security/cve/CVE-2017-5715, https://www.suse.com/security/cve/CVE-2017-5753, https://www.suse.com/security/cve/CVE-2017-5754

    Affected packages

    Package

    Name: nutch

    Purl: pkg:rpm/suse/nutch&distro=SUSE%20Manager%20Server%203.0

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0-0.9.8.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2018:0285-1 | CVE-DB