SUSE-SU-2019:0341-1

    Dashboard / Vulnerabilities / SUSE-SU-2019:0341-1

    SUSE-SU-2019:0341-1

    Published: 13 Feb 2019Last Modified: 2 May 2025
    Upstream:

    Summary: Security update for SUSE Manager Server 3.2

    Details: This update fixes the following issues: branch-network-formula: - Netconfig update requires bind directory to exists for bind forward, ensure it (bsc#1116365) - Rework network update in branch-network formula (bsc#1116365) py26-compat-salt: - Remove arch from name when pkg.list_pkgs is called with 'attr' (bsc#1114029) python-susemanager-retail: - Force one python version for SLE12 (python2) and SLE15 (python3) - Add disklabel: none to migrated RAID saltboot-formula: - Use FTP active mode for image download - Always deploy image when image is specified in partitioning pillar (bsc#1119807) - Call blockdev.formatted with force=True - Allow RAID images to be defined by saltboot formula - image information can be provided directly for disk - allow 'none' disk label in formula and in that case hide partitioning information smdba: - Tuning: add cpu_tuple_cost (bsc#1105791) spacecmd: - Fix importing state channels using configchannel_import - Fix getting file info for latest revision (via configchannel_filedetails) - Add functions to merge errata (softwarechannel_errata_merge) and packages (softwarechannel_mergepackages) through spacecmd (bsc#987798) spacewalk-admin: - Use a Salt engine to process return results (bsc#1099988) spacewalk-backend: - Move channel update close to commit to avoid long lock (bsc#1121424) - Adapt Inter Server Sync code to new SCC sync backend - Fix issue raising exceptions 'with_traceback' on Python 2 - Hide Python traceback and show only error message (bsc#1110427) - Honor renamed postgresql10 log directory for supportconfig spacewalk-branding: - Better label visualization when the input is disabled. (bsc#1110772) spacewalk-client-tools: - Fix XML-RPC type serialization (bsc#1116610) spacewalk-java: - Improve salt events processing performance (bsc#1125097) - Prevent an error when onboarding a RES 6 minion (bsc#1124794) - Support products with multiple base channels - Fix ordering of base channels to prevent synchronization errors (bsc#1123902) - Support products with multiple base channels - Avoid a NullPointerException error in Taskomatic (bsc#1119271) - Reset channel assignments when base channel changes on registration (bsc#1118917) - Allow bootstrapping minions with a pending minion key being present (bsc#1119727) - Hide 'unknown virtual host manager' when virtual host manager of all hosts is known (bsc#1119320) - Disable notification types with 'java.notifications_type_disabled' in rhn.conf (bsc#1111910) - Change SCC sync backend to adapt quicker to SCC changes and improve speed of syncing metadata and checking for channel dependencies (bsc#1089121) - Read OEM Orderitems from DB instead of create always new items (bsc#1098826) - Fix mgr-sync refresh when subscription was removed (bsc#1105720) - XMLRPC API: Include init.sls in channel file list (bsc#1111191) - Fix the config channels assignment via SSM (bsc#1117759) - Install product packages during bootstrapping minions (bsc#1104680) - Fix cloning channels when managing the same errata for both vendor and private orgs (bsc#1111686) - Introduce Loggerhead-module.js to store logs from the frontend - Removed 'Manage Channels' shortcut for vendor channels (bsc#1115978) - Hide already applied errata and channel entries from the output list in audit.listSystemsByPatchStatus (bsc#1111963) - Prevent failing KickstartCommand when customPosition is null (bsc#1112121) - Automatically schedule an Action to refresh minion repos after deletion of an assigned channel (bsc#1115029) - Performance improvements in channel management functionalities (bsc#1114877) - Handle with an error message if state file fails to render (bsc#1110757) - When changing basechannel the compatible old childchannels are now selected by default. (bsc#1110772) - Add check for yast autoinstall profiles when setting kickstartTree (bsc#1114115) - Use a Salt engine to process return results (bsc#1099988) - Fix handling of CVEs including multiple patches in CVE audit (bsc#1111963) - Fix synchronizing Expanded Support Channel with missing architecture (bsc#1122565) spacewalk-setup: - Use a Salt engine to process return results (bsc#1099988) spacewalk-utils: - Exit with an error if spacewalk-common-channels does not match any channel spacewalk-web: - Show feedback messages after using the retry option on the notification messages page - Change SCC sync backend to adapt quicker to SCC changes and improve speed of syncing metadata and checking for channel dependencies - Fix wording for taskotop (cosmetical only)(bsc#1118112) - When changing basechannel the compatible old childchannels are now selected by default. (bsc#1110772) subscription-matcher: - Old style hard bundle merging fix (bsc#1114059) susemanager: - Add bootstrap repo definition for OES 2018 SP1 (bsc#1116826) - Rhnlib was renamed to python2-rhnlib. Change bootstrap data accordingly. - Change SCC sync backend to adapt quicker to SCC changes and improve speed of syncing metadata and checking for channel dependencies - Adapt mgr-create-bootstrap-repo for Uyuni and let it create bootstrap repos for openSUSE and CentOS - Fetch packages from correct channel when creating a bootstrap repository - Fix not found package on mgr-create-bootstrap-repo for SLE-15-s390x (bsc#1116566) - Add python3-six to bootstrap repo for SLES15 (bsc#1118478) susemanager-docs_en: - Update text and image files. - Enhance forms documentation (more attributes). - Proxy: for example, migration from traditional to Salt not supported. - RAM requirements for host running kiwi OS images. - Notification properties. - Update scalability documentation. susemanager-schema: - Change SCC sync backend to adapt quicker to SCC changes and improve speed of syncing metadata and checking for channel dependencies - Performance improvements in channel management functionalities (bsc#1114877) - Use a Salt engine to process return results (bsc#1099988) susemanager-sls: - Improve salt events processing performance (bsc#1125097) - Allow bootstrapping minions with a pending minion key being present (bsc#1119727) - Use a Salt engine to process return results (bsc#1099988) susemanager-sync-data: - Make SUSE Manager Tools channel mandatory (bsc#1123983) - Add sle-module-web-scripting for OES2018 (bsc#1119233) - Add new set of data for the new SCC sync backend - Enable SLE15 SP1 family (bsc#1114268) - Enable OES2018 SP1 (bsc#1116826) tika-core: - CVE-2018-17197: Fixed an infinite loop in the SQLite3Parser of Apache Tika (bsc#1121038)

    References: https://www.suse.com/support/update/announcement/2019/suse-su-20190341-1/, https://bugzilla.suse.com/1089121, https://bugzilla.suse.com/1098826, https://bugzilla.suse.com/1099988, https://bugzilla.suse.com/1104680, https://bugzilla.suse.com/1105720, https://bugzilla.suse.com/1105791, https://bugzilla.suse.com/1110427, https://bugzilla.suse.com/1110757, https://bugzilla.suse.com/1110772, https://bugzilla.suse.com/1111191, https://bugzilla.suse.com/1111686, https://bugzilla.suse.com/1111910, https://bugzilla.suse.com/1111963, https://bugzilla.suse.com/1112121, https://bugzilla.suse.com/1114029, https://bugzilla.suse.com/1114059, https://bugzilla.suse.com/1114115, https://bugzilla.suse.com/1114268, https://bugzilla.suse.com/1114877, https://bugzilla.suse.com/1115029, https://bugzilla.suse.com/1115978, https://bugzilla.suse.com/1116365, https://bugzilla.suse.com/1116566, https://bugzilla.suse.com/1116610, https://bugzilla.suse.com/1116826, https://bugzilla.suse.com/1117759, https://bugzilla.suse.com/1118112, https://bugzilla.suse.com/1118478, https://bugzilla.suse.com/1118917, https://bugzilla.suse.com/1119233, https://bugzilla.suse.com/1119271, https://bugzilla.suse.com/1119320, https://bugzilla.suse.com/1119727, https://bugzilla.suse.com/1119807, https://bugzilla.suse.com/1121038, https://bugzilla.suse.com/1121424, https://bugzilla.suse.com/1122565, https://bugzilla.suse.com/1123902, https://bugzilla.suse.com/1123983, https://bugzilla.suse.com/1124794, https://bugzilla.suse.com/1125097, https://bugzilla.suse.com/987798, https://www.suse.com/security/cve/CVE-2018-17197

    Affected packages

    Package

    Name: spacewalk-backend

    Purl: pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Proxy%203.2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.8.57.8-3.10.14

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High