SUSE-SU-2019:3097-1
Dashboard / Vulnerabilities / SUSE-SU-2019:3097-1
SUSE-SU-2019:3097-1
Summary: Security update for cloud-init
Details: This update for cloud-init to version 19.2 fixes the following issues: Security issue fixed: - CVE-2019-0816: Fixed the unnecessary extra ssh keys that were added to authorized_keys (bsc#1129124). Non-security issues fixed: - Short circuit the conditional for identifying the sysconfig renderer (bsc#1154092, bsc#1142988). - If /etc/resolv.conf is a symlink, break it. This will avoid netconfig from clobbering the changes cloud-init applied (bsc#1151488).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20193097-1/, https://bugzilla.suse.com/1099358, https://bugzilla.suse.com/1129124, https://bugzilla.suse.com/1136440, https://bugzilla.suse.com/1142988, https://bugzilla.suse.com/1144363, https://bugzilla.suse.com/1151488, https://bugzilla.suse.com/1154092, https://www.suse.com/security/cve/CVE-2019-0816
Affected packages
Package
Name: cloud-init
Purl: pkg:rpm/suse/cloud-init&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015
Affected ranges
Type: ECOSYSTEM
Events:
