SUSE-SU-2018:1736-1
Dashboard / Vulnerabilities / SUSE-SU-2018:1736-1
SUSE-SU-2018:1736-1
Summary: Security update for cobbler
Details: This update for cobbler fixes the following issues: The following security issue has been fixed: - CVE-2017-1000469: Escape shell parameters provided by the user for the reposync action. (bsc#1074594) Additionally, the following non-security issues have been fixed: - Fix signature for SLES15. (bsc#1075014) - Detect if there is already another instance of 'cobbler sync' running and exit with failure if so. (bsc#1081714) - Add SLES 15 distro profile. (bsc#1090205) - Require tftp(server) instead of atftp.
References: https://www.suse.com/support/update/announcement/2018/suse-su-20181736-1/, https://bugzilla.suse.com/1074594, https://bugzilla.suse.com/1075014, https://bugzilla.suse.com/1081714, https://bugzilla.suse.com/1090205, https://www.suse.com/security/cve/CVE-2017-1000469
Affected packages
Package
Name: cobbler
Purl: pkg:rpm/suse/cobbler&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
