Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0473-1

Опубликовано: 25 мар. 2021
Источник: suse-cvrf

Описание

Security update for hawk2

This update for hawk2 fixes the following issues:

  • Update to version 2.6.3:
    • Remove hawk_invoke and use capture3 instead of runas (bsc#1179999)(CVE-2020-35459)
    • Remove unnecessary chmod (bsc#1182166)(CVE-2021-25314)
    • Sanitize filename to contains whitelist of alphanumeric (bsc#1182165)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.2
hawk2-2.6.3+git.1614684118.af555ad9-lp152.2.18.1

Описание

An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.


Затронутые продукты
openSUSE Leap 15.2:hawk2-2.6.3+git.1614684118.af555ad9-lp152.2.18.1

Ссылки

Описание

A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue affects: SUSE Linux Enterprise High Availability 12-SP3 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 12-SP5 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 15-SP2 hawk2 versions prior to 2.6.3+git.1614684118.af555ad9.


Затронутые продукты
openSUSE Leap 15.2:hawk2-2.6.3+git.1614684118.af555ad9-lp152.2.18.1

Ссылки