Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1580-2

Опубликовано: 08 июл. 2020
Источник: suse-cvrf

Описание

Security update for texlive-filesystem

This update for texlive-filesystem fixes the following issues:

Security issues fixed:

  • CVE-2020-8016: Fixed a race condition in the spec file (bsc#1159740).
  • CVE-2020-8017: Fixed a race condition on a cron job (bsc#1158910).

Список пакетов

SUSE Linux Enterprise Module for Desktop Applications 15 SP2
texlive-collection-basic-2017.135.svn41616-9.12.1
texlive-collection-bibtexextra-2017.135.svn44385-9.12.1
texlive-collection-binextra-2017.135.svn44515-9.12.1
texlive-collection-context-2017.135.svn42330-9.12.1
texlive-collection-fontsextra-2017.135.svn43356-9.12.1
texlive-collection-fontsrecommended-2017.135.svn35830-9.12.1
texlive-collection-fontutils-2017.135.svn37105-9.12.1
texlive-collection-formatsextra-2017.135.svn44177-9.12.1
texlive-collection-games-2017.135.svn42992-9.12.1
texlive-collection-humanities-2017.135.svn42268-9.12.1
texlive-collection-langarabic-2017.135.svn44496-9.12.1
texlive-collection-langchinese-2017.135.svn42675-9.12.1
texlive-collection-langcjk-2017.135.svn43009-9.12.1
texlive-collection-langcyrillic-2017.135.svn44401-9.12.1
texlive-collection-langczechslovak-2017.135.svn32550-9.12.1
texlive-collection-langenglish-2017.135.svn43650-9.12.1
texlive-collection-langeuropean-2017.135.svn44414-9.12.1
texlive-collection-langfrench-2017.135.svn40375-9.12.1
texlive-collection-langgerman-2017.135.svn42045-9.12.1
texlive-collection-langgreek-2017.135.svn44192-9.12.1
texlive-collection-langitalian-2017.135.svn30372-9.12.1
texlive-collection-langjapanese-2017.135.svn44554-9.12.1
texlive-collection-langkorean-2017.135.svn42106-9.12.1
texlive-collection-langother-2017.135.svn44414-9.12.1
texlive-collection-langpolish-2017.135.svn44371-9.12.1
texlive-collection-langportuguese-2017.135.svn30962-9.12.1
texlive-collection-langspanish-2017.135.svn40587-9.12.1
texlive-collection-latex-2017.135.svn41614-9.12.1
texlive-collection-latexextra-2017.135.svn44544-9.12.1
texlive-collection-latexrecommended-2017.135.svn44177-9.12.1
texlive-collection-luatex-2017.135.svn44500-9.12.1
texlive-collection-mathscience-2017.135.svn44396-9.12.1
texlive-collection-metapost-2017.135.svn44297-9.12.1
texlive-collection-music-2017.135.svn40561-9.12.1
texlive-collection-pictures-2017.135.svn44395-9.12.1
texlive-collection-plaingeneric-2017.135.svn44177-9.12.1
texlive-collection-pstricks-2017.135.svn44460-9.12.1
texlive-collection-publishers-2017.135.svn44485-9.12.1
texlive-collection-xetex-2017.135.svn43059-9.12.1
texlive-devel-2017.135-9.12.1
texlive-extratools-2017.135-9.12.1
texlive-filesystem-2017.135-9.12.1
texlive-scheme-basic-2017.135.svn25923-9.12.1
texlive-scheme-context-2017.135.svn35799-9.12.1
texlive-scheme-full-2017.135.svn44177-9.12.1
texlive-scheme-gust-2017.135.svn44177-9.12.1
texlive-scheme-infraonly-2017.135.svn41515-9.12.1
texlive-scheme-medium-2017.135.svn44177-9.12.1
texlive-scheme-minimal-2017.135.svn13822-9.12.1
texlive-scheme-small-2017.135.svn41825-9.12.1
texlive-scheme-tetex-2017.135.svn44187-9.12.1

Описание

A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users to corrupt files or potentially escalate privileges. This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-basic-2017.135.svn41616-9.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-bibtexextra-2017.135.svn44385-9.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-binextra-2017.135.svn44515-9.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-context-2017.135.svn42330-9.12.1

Ссылки

Описание

A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-basic-2017.135.svn41616-9.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-bibtexextra-2017.135.svn44385-9.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-binextra-2017.135.svn44515-9.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP2:texlive-collection-context-2017.135.svn42330-9.12.1

Ссылки