Описание
Security update for hawk2
This update for hawk2 fixes the following issues:
- Update to version 2.6.3:
- Remove hawk_invoke and use capture3 instead of runas (bsc#1179999)(CVE-2020-35459)
- Remove unnecessary chmod (bsc#1182166)(CVE-2021-25314)
- Sanitize filename to contains whitelist of alphanumeric (bsc#1182165)
Список пакетов
SUSE Linux Enterprise High Availability Extension 12 SP3
Ссылки
- Link for SUSE-SU-2021:0943-1
- E-Mail link for SUSE-SU-2021:0943-1
- SUSE Security Ratings
- SUSE Bug 1179999
- SUSE Bug 1182165
- SUSE Bug 1182166
- SUSE CVE CVE-2020-35459 page
- SUSE CVE CVE-2021-25314 page
Описание
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
Затронутые продукты
Ссылки
- CVE-2020-35459
- SUSE Bug 1179999
Описание
A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue affects: SUSE Linux Enterprise High Availability 12-SP3 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 12-SP5 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 15-SP2 hawk2 versions prior to 2.6.3+git.1614684118.af555ad9.
Затронутые продукты
Ссылки
- CVE-2021-25314
- SUSE Bug 1182166
- SUSE Bug 1183693