Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2022:0727-1

Опубликовано: 04 мар. 2022
Источник: suse-cvrf

Описание

Security update for libeconf, shadow and util-linux

This security update for libeconf, shadow and util-linux fix the following issues:

libeconf:

  • Add libeconf to SLE-Module-Basesystem_15-SP3 because needed by 'util-linux' and 'shadow' to fix autoyast handling of security related parameters (bsc#1192954, jsc#SLE-23384, jsc#SLE-23402)

Issues fixed in libeconf:

  • Reading numbers with different bases (e.g. oktal) (bsc#1193632) (#157)
  • Fixed different issues while writing string values to file.
  • Writing comments to file too.
  • Fixed crash while merging values.
  • Added econftool cat option (#146)
  • new API call: econf_readDirsHistory (showing ALL locations)
  • new API call: econf_getPath (absolute path of the configuration file)
  • Man pages libeconf.3 and econftool.8.
  • Handling multiline strings.
  • Added libeconf_ext which returns more information like line_nr, comments, path of the configuration file,...
  • Econftool, an command line interface for handling configuration files.
  • Generating HTML API documentation with doxygen.
  • Improving error handling and semantic file check.
  • Joining entries with the same key to one single entry if env variable ECONF_JOIN_SAME_ENTRIES has been set.

shadow:

  • The legacy code does not support /etc/login.defs.d used by YaST. Enable libeconf to read it (bsc#1192954, jsc#SLE-23384, jsc#SLE-23402)

util-linux:

  • The legacy code does not support /etc/login.defs.d used by YaST. Enable libeconf to read it (bsc#1192954, jsc#SLE-23384, jsc#SLE-23402)
  • Allow use of larger values for start sector to prevent blockdev --report aborting (bsc#1188507)
  • Fixed blockdev --report using non-space characters as a field separator (bsc#1188507)
  • CVE-2021-3995: Fixed unauthorized unmount in util-linux's libmount. (bsc#1194976)
  • CVE-2021-3996: Fixed unauthorized unmount in util-linux's libmount. (bsc#1194976)

Список пакетов

openSUSE Leap 15.3
libblkid-devel-2.36.2-150300.4.14.3
libblkid-devel-32bit-2.36.2-150300.4.14.3
libblkid-devel-static-2.36.2-150300.4.14.3
libblkid1-2.36.2-150300.4.14.3
libblkid1-32bit-2.36.2-150300.4.14.3
libeconf-devel-0.4.4+git20220104.962774f-150300.3.6.2
libeconf0-0.4.4+git20220104.962774f-150300.3.6.2
libeconf0-32bit-0.4.4+git20220104.962774f-150300.3.6.2
libfdisk-devel-2.36.2-150300.4.14.3
libfdisk-devel-32bit-2.36.2-150300.4.14.3
libfdisk-devel-static-2.36.2-150300.4.14.3
libfdisk1-2.36.2-150300.4.14.3
libfdisk1-32bit-2.36.2-150300.4.14.3
libmount-devel-2.36.2-150300.4.14.3
libmount-devel-32bit-2.36.2-150300.4.14.3
libmount-devel-static-2.36.2-150300.4.14.3
libmount1-2.36.2-150300.4.14.3
libmount1-32bit-2.36.2-150300.4.14.3
libsmartcols-devel-2.36.2-150300.4.14.3
libsmartcols-devel-32bit-2.36.2-150300.4.14.3
libsmartcols-devel-static-2.36.2-150300.4.14.3
libsmartcols1-2.36.2-150300.4.14.3
libsmartcols1-32bit-2.36.2-150300.4.14.3
libuuid-devel-2.36.2-150300.4.14.3
libuuid-devel-32bit-2.36.2-150300.4.14.3
libuuid-devel-static-2.36.2-150300.4.14.3
libuuid1-2.36.2-150300.4.14.3
libuuid1-32bit-2.36.2-150300.4.14.3
login_defs-4.8.1-150300.4.3.8
python3-libmount-2.36.2-150300.4.14.2
shadow-4.8.1-150300.4.3.8
util-linux-2.36.2-150300.4.14.3
util-linux-lang-2.36.2-150300.4.14.3
util-linux-systemd-2.36.2-150300.4.14.2
uuidd-2.36.2-150300.4.14.2

Описание

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.


Затронутые продукты
openSUSE Leap 15.3:libblkid-devel-2.36.2-150300.4.14.3
openSUSE Leap 15.3:libblkid-devel-32bit-2.36.2-150300.4.14.3
openSUSE Leap 15.3:libblkid-devel-static-2.36.2-150300.4.14.3
openSUSE Leap 15.3:libblkid1-2.36.2-150300.4.14.3

Ссылки

Описание

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.


Затронутые продукты
openSUSE Leap 15.3:libblkid-devel-2.36.2-150300.4.14.3
openSUSE Leap 15.3:libblkid-devel-32bit-2.36.2-150300.4.14.3
openSUSE Leap 15.3:libblkid-devel-static-2.36.2-150300.4.14.3
openSUSE Leap 15.3:libblkid1-2.36.2-150300.4.14.3

Ссылки
Уязвимость openSUSE-SU-2022:0727-1