SUSE-SU-2019:0654-1
Dashboard / Vulnerabilities / SUSE-SU-2019:0654-1
SUSE-SU-2019:0654-1
Summary: Security update for openwsman
Details: This update for openwsman fixes the following issues: Security issues fixed: - CVE-2019-3816: Fixed a vulnerability in openwsmand deamon which could lead to arbitary file disclosure (bsc#1122623). - CVE-2019-3833: Fixed a vulnerability in process_connection() which could allow an attacker to trigger an infinite loop which leads to Denial of Service (bsc#1122623). Other issues addressed: - Added OpenSSL 1.1 compatibility - Compilation in debug mode fixed - Directory listing without authentication fixed (bsc#1092206).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20190654-1/, https://bugzilla.suse.com/1092206, https://bugzilla.suse.com/1122623, https://www.suse.com/security/cve/CVE-2019-3816, https://www.suse.com/security/cve/CVE-2019-3833
Affected packages
Package
Name: openwsman
Purl: pkg:rpm/suse/openwsman&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015
Affected ranges
Type: ECOSYSTEM
Events:
