openSUSE-SU-2019:1111-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1111-1
openSUSE-SU-2019:1111-1
Summary: Security update for openwsman
Details: This update for openwsman fixes the following issues: Security issues fixed: - CVE-2019-3816: Fixed a vulnerability in openwsmand deamon which could lead to arbitary file disclosure (bsc#1122623). - CVE-2019-3833: Fixed a vulnerability in process_connection() which could allow an attacker to trigger an infinite loop which leads to Denial of Service (bsc#1122623). Other issues addressed: - Added OpenSSL 1.1 compatibility - Compilation in debug mode fixed - Directory listing without authentication fixed (bsc#1092206). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/KFUBWPIQNXTWDIPGMP4SO3OSCZDHINE4/#KFUBWPIQNXTWDIPGMP4SO3OSCZDHINE4, https://bugzilla.suse.com/1092206, https://bugzilla.suse.com/1122623, https://www.suse.com/security/cve/CVE-2019-3816, https://www.suse.com/security/cve/CVE-2019-3833
Affected packages
Package
Name: openwsman
Purl: pkg:rpm/opensuse/openwsman&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
