Описание
Security update for booth
This update for booth fixes the following issues:
- CVE-2022-2553: authfile directive in booth config file is completely ignored (bsc#1201946).
Список пакетов
SUSE Linux Enterprise High Availability GEO Extension 12 SP4
booth-1.0-42.3.1
SUSE Linux Enterprise High Availability GEO Extension 12 SP5
booth-1.0-42.3.1
Ссылки
- Link for SUSE-SU-2022:2605-1
- E-Mail link for SUSE-SU-2022:2605-1
- SUSE Security Ratings
- SUSE Bug 1201946
- SUSE CVE CVE-2022-2553 page
Описание
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
Затронутые продукты
SUSE Linux Enterprise High Availability GEO Extension 12 SP4:booth-1.0-42.3.1
SUSE Linux Enterprise High Availability GEO Extension 12 SP5:booth-1.0-42.3.1
Ссылки
- CVE-2022-2553
- SUSE Bug 1201946