Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0351-1

Опубликовано: 06 фев. 2020
Источник: suse-cvrf

Описание

Security update for wicked

This update for wicked fixes the following issues:

Security issues fixed:

  • CVE-2019-18902: Fixed a use-after-free when receiving invalid DHCP6 client options (bsc#1160903).
  • CVE-2019-18903: Fixed a use-after-free when receiving invalid DHCP6 IA_PD option (bsc#1160904).
  • CVE-2020-7216: Fixed a potential denial of service via a memory leak when processing packets with missing message type option in DHCP4 (bsc#1160905).
  • CVE-2020-7217: Fixed a memory leak in DHCP4 fsm when processing packets for other client ids (bsc#1160906).

Non-security issue fixed:

  • dhcp4: Fixed an intermittent hang during network setup by cleaning up the defer timer pointer (bsc#1142214).

Список пакетов

Image SLES12-SP5-Azure-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-HPC-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-HPC-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-SAP-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-SAP-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-Standard-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-EC2-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-EC2-ECS-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-EC2-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-EC2-SAP-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-EC2-SAP-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-GCE-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-GCE-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-GCE-SAP-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-GCE-SAP-On-Demand
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-OCI-BYOS-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
SUSE Linux Enterprise Server 12 SP5
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
wicked-0.6.60-3.5.1
wicked-service-0.6.60-3.5.1

Описание

A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.6.1. openSUSE Factory wicked versions prior to 0.6.62.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-BYOS:wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-service-0.6.60-3.5.1

Ссылки

Описание

A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.9.1. openSUSE Factory wicked versions prior to 0.6.62.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-BYOS:wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-service-0.6.60-3.5.1

Ссылки

Описание

An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-BYOS:wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-service-0.6.60-3.5.1

Ссылки

Описание

An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-BYOS:wicked-service-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-0.6.60-3.5.1
Image SLES12-SP5-Azure-Basic-On-Demand:wicked-service-0.6.60-3.5.1

Ссылки
Уязвимость SUSE-SU-2020:0351-1