Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:14833-1

Опубликовано: 27 окт. 2021
Источник: suse-cvrf

Описание

Security update for SUSE Manager Client Tools

This update fixes the following issues:

salt:

  • Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265) (CVE-2021-21996)

spacecmd:

  • Version 4.2.13-1
    • Update translation strings
    • configchannel_updatefile handles directory properly (bsc#1190512)
    • Add schedule_archivecompleted to mass archive actions (bsc#1181223)
    • Remove whoami from the list of unauthenticated commands (bsc#1188977)

spacewalk-client-tools:

  • Version 4.2.14-1
    • Update translation strings

Список пакетов

SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS
python2-spacewalk-check-4.2.14-27.59.1
python2-spacewalk-client-setup-4.2.14-27.59.1
python2-spacewalk-client-tools-4.2.14-27.59.1
salt-2016.11.10-43.84.1
salt-doc-2016.11.10-43.84.1
salt-minion-2016.11.10-43.84.1
spacecmd-4.2.13-18.93.1
spacewalk-check-4.2.14-27.59.1
spacewalk-client-setup-4.2.14-27.59.1
spacewalk-client-tools-4.2.14-27.59.1
SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS
python2-spacewalk-check-4.2.14-27.59.1
python2-spacewalk-client-setup-4.2.14-27.59.1
python2-spacewalk-client-tools-4.2.14-27.59.1
salt-2016.11.10-43.84.1
salt-doc-2016.11.10-43.84.1
salt-minion-2016.11.10-43.84.1
spacecmd-4.2.13-18.93.1
spacewalk-check-4.2.14-27.59.1
spacewalk-client-setup-4.2.14-27.59.1
spacewalk-client-tools-4.2.14-27.59.1

Описание

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-spacewalk-check-4.2.14-27.59.1
SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-spacewalk-client-setup-4.2.14-27.59.1
SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-spacewalk-client-tools-4.2.14-27.59.1
SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:salt-2016.11.10-43.84.1

Ссылки