SUSE-SU-2019:2521-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2521-1
SUSE-SU-2019:2521-1
Summary: Security update for SUSE Manager Server 3.2
Details: This update fixes the following issues: cobbler: - Jinja2 template library fix (bsc#1141661) pgjdbc-ng: - Allow dots in database name (bsc#1146416) py26-compat-salt: - Get tornado dependency from the system on SLE12 (bsc#1149409) - Catch SSLError for TLS 1.2 bootstraps with RES/RHEL6 and SLE11 (bsc#1147126) spacecmd: - Check that a channel doesn't have clones before deleting it (bsc#1138454) spacewalk-backend: - Remove credentials also from potential rhn.conf backup files in spacewalk-debug (bsc#1146419) - Do not make 'rhn-satellite-exporter' to crash with 'AttributeError' (bsc#1146869) - Spacewalk-remove-channel check that channel doesn't have cloned channels before deleting it (bsc#1138454) - Prevent duplicate changelog entries due VARCHAR(3000) db text column (bsc#1144889) - Avoid traceback on mgr-inter-sync when exception message contains UTF8 characters or there are problems with the package cache (bsc#1143016) registered guest (bsc#1093381) spacewalk-branding: - Add missing strings for task status page spacewalk-client-tools: - Invalidate cache 5 minutes before actual expiration(bsc#1143562) spacewalk-java: - Add UI message when salt-formulas system folders are unreachable (bsc#1142309) - Don't convert localhost repositories URL in mirror case (bsc#1135957) - Check that a channel doesn't have clones before deleting it (bsc#1138454) - Improve websocket authentication to prevent errors in logs (bsc#1138454) - Normalize date formats for actions, notifications and clm (bsc#1142774) - Cloning Errata from a specific channel should not take packages from other channels (bsc#1142764) - Add susemanager as prerequired for spacewalk-java - Improve performance for retrieving the user permissions on channels (bsc#1140644) - Prerequire salt package to avoid not existing user issues - Support partly patched CVEs in CVE audit (bsc#1137229) spacewalk-setup: - Configure 150 Tomcat workers by default, matching httpds MaxClients spacewalk-utils: - Common-channels: Fix repo type assignment for type YUM - Adds support for Ubuntu and Debian channels to spacewalk-common-channels. spacewalk-web: - Fix the 'include recommended' button on channels selection in SSM (bsc#1145086) - Normalize date formats for actions, notifications and clm (bsc#1142774) - Add unsupported browser warning when using Internet Explorer susemanager: - Dmidecode does not exist on s390x (bsc#1145119) susemanager-docs_en: - Add link to the creation of the bootstrap script (bsc#1146895). - Improve adoc tagging. - LimitNOFILE back-port. - Fix command-line error (bsc#1096426). susemanager-schema: - Improve performance for retrieving the user permissions on channels (bsc#1140644) susemanager-sls: - Bootstrapping RES6/RHEL6/SLE11 with TLS1.2 now shows error message. (bsc#1147126) - Dmidecode does not exist on ppc64le and s390x (bsc#1145119) - Update susemanager.conf to use adler32 for computing the server_id for new minions tika-core: New upstream version 1.2.2. Fixes security issues: - CVE-2019-10088: Fixed an OOM from a crafted Zip File in Apache Tika's RecursiveParserWrapper (bsc#1144500). - CVE-2019-10093: Fixed a Denial of Service in Apache Tika's 2003ml and 2006ml Parsers (bsc#1144510). - CVE-2019-10094: Fixed a stack overflow from crafted compressed files in Apache Tika's RecursiveParserWrapper (bsc#1144515).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192521-1/, https://bugzilla.suse.com/1093381, https://bugzilla.suse.com/1096426, https://bugzilla.suse.com/1135957, https://bugzilla.suse.com/1137229, https://bugzilla.suse.com/1138454, https://bugzilla.suse.com/1140644, https://bugzilla.suse.com/1141661, https://bugzilla.suse.com/1142309, https://bugzilla.suse.com/1142764, https://bugzilla.suse.com/1142774, https://bugzilla.suse.com/1143016, https://bugzilla.suse.com/1143562, https://bugzilla.suse.com/1144500, https://bugzilla.suse.com/1144510, https://bugzilla.suse.com/1144515, https://bugzilla.suse.com/1144889, https://bugzilla.suse.com/1145086, https://bugzilla.suse.com/1145119, https://bugzilla.suse.com/1146416, https://bugzilla.suse.com/1146419, https://bugzilla.suse.com/1146869, https://bugzilla.suse.com/1146895, https://bugzilla.suse.com/1147126, https://bugzilla.suse.com/1149409, https://www.suse.com/security/cve/CVE-2019-10088, https://www.suse.com/security/cve/CVE-2019-10093, https://www.suse.com/security/cve/CVE-2019-10094
Affected packages
Package
Name: cobbler
Purl: pkg:rpm/suse/cobbler&distro=SUSE%20Manager%20Server%203.2
Affected ranges
Type: ECOSYSTEM
Events:
