Описание
Security update for slurm
This update for slurm fixes the following issues:
-
Fix interaction with systemd: systemd expects that a daemonizing process doesn't go away until the PID file with it PID of the daemon has bee written (bsc#1084125).
-
Make sure systemd services get restarted only when all packages are in a consistent state, not in the middle of an 'update' transaction (bsc#1088693). Since the %postun scripts that run on update are from the old package they cannot be changed - thus we work around the restart breakage.
-
CVE-2018-7033: Fixed security issue in accounting_storage/mysql plugin by always escaping strings within the slurmdbd (bsc#1085240).
Список пакетов
SUSE Linux Enterprise Module for HPC 12
Ссылки
- Link for SUSE-SU-2018:0987-1
- E-Mail link for SUSE-SU-2018:0987-1
- SUSE Security Ratings
- SUSE Bug 1084125
- SUSE Bug 1085240
- SUSE Bug 1088693
- SUSE CVE CVE-2018-7033 page
Описание
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
Затронутые продукты
Ссылки
- CVE-2018-7033
- SUSE Bug 1085240