Описание
Security update for SUSE Manager Client Tools Beta
This update for SUSE Manager Client Tools Beta fixes the following issues:
- Changed codestream origin of SUSE Manager Client Tools Beta (no source changes)
icinga in SUSE Manager Client Tools Beta also received the following security fixes:
- CVE-2016-9566: Fixed root privilege escalation (bsc#1014637)
- CVE-2019-3698 : Symbolic Link (Symlink) following vulnerability in the cronjob allows local attackers to cause cause DoS or potentially escalate privileges by winning a race (bsc#1156309)
Список пакетов
Image SLES12-SP5-Azure-BYOS
Image SLES12-SP5-Azure-Basic-On-Demand
Image SLES12-SP5-Azure-HPC-BYOS
Image SLES12-SP5-Azure-SAP-BYOS
Image SLES12-SP5-Azure-Standard-On-Demand
Image SLES12-SP5-EC2-BYOS
Image SLES12-SP5-EC2-ECS-On-Demand
Image SLES12-SP5-EC2-On-Demand
Image SLES12-SP5-EC2-SAP-BYOS
Image SLES12-SP5-GCE-BYOS
Image SLES12-SP5-GCE-On-Demand
Image SLES12-SP5-GCE-SAP-BYOS
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
SUSE Linux Enterprise Module for Advanced Systems Management 12
SUSE Linux Enterprise Module for Containers 12
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE Linux Enterprise Workstation Extension 12 SP5
SUSE Manager Client Tools 12
SUSE Manager Client Tools 12-BETA
Ссылки
- Link for SUSE-SU-2024:1629-1
- E-Mail link for SUSE-SU-2024:1629-1
- SUSE Security Ratings
- SUSE Bug 1014637
- SUSE Bug 1156309
- SUSE CVE CVE-2016-9566 page
- SUSE CVE CVE-2019-3698 page
Описание
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
Затронутые продукты
Ссылки
- CVE-2016-9566
- SUSE Bug 1014637
Описание
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.
Затронутые продукты
Ссылки
- CVE-2019-3698
- SUSE Bug 1150550
- SUSE Bug 1156309