SUSE-SU-2019:1122-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1122-1
SUSE-SU-2019:1122-1
Summary: Security update for hostinfo, supportutils
Details: This update for hostinfo, supportutils fixes the following issues: Security issues fixed for supportutils: - CVE-2018-19640: Fixed an issue where users could kill arbitrary processes (bsc#1118463). - CVE-2018-19638: Fixed an issue where users could overwrite arbitrary log files (bsc#1118460). - CVE-2018-19639: Fixed a code execution if run with -v (bsc#1118462). - CVE-2018-19637: Fixed an issue where static temporary filename could allow overwriting of files (bsc#1117776). - CVE-2018-19636: Fixed a local root exploit via inclusion of attacker controlled shell script (bsc#1117751). Other issues fixed for supportutils: - Fixed invalid exit code commands (bsc#1125666) - SUSE separation in supportconfig (bsc#1125623) - Clarified supportconfig(8) -x option (bsc#1115245) - supportconfig: 3.0.127 - btrfs filesystem usage - List products.d - Dump lsof errors - Added ha commands for corosync - Dumped find errors in ib_info Issues fixed in hostinfo: - Removed extra kernel install dates (bsc#1099498) - Resolved network bond issue (bsc#1054979)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191122-1/, https://bugzilla.suse.com/1054979, https://bugzilla.suse.com/1099498, https://bugzilla.suse.com/1115245, https://bugzilla.suse.com/1117751, https://bugzilla.suse.com/1117776, https://bugzilla.suse.com/1118460, https://bugzilla.suse.com/1118462, https://bugzilla.suse.com/1118463, https://bugzilla.suse.com/1125623, https://bugzilla.suse.com/1125666, https://www.suse.com/security/cve/CVE-2018-19636, https://www.suse.com/security/cve/CVE-2018-19637, https://www.suse.com/security/cve/CVE-2018-19638, https://www.suse.com/security/cve/CVE-2018-19639, https://www.suse.com/security/cve/CVE-2018-19640
Affected packages
Package
Name: hostinfo
Purl: pkg:rpm/suse/hostinfo&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type: ECOSYSTEM
Events:
