QID 174822

QID 174822: SUSE Enterprise Linux Security update for SUSE Manager Proxy 4.1 (SUSE-SU-2021:0906-1)

This update fixes the following issues:

mgr-osad:

- Adapt to new SSL implementation of rhnlib (bsc#1181807)

rhnlib:

- Change SSL implementation to python ssl for better SAN and hostname
matching support (bsc#1181807)

spacewalk-backend:

- Open repomd files as binary (bsc#1173893)
- Fix requesting Release file in debian repos (bsc#1182006)
- Reposync: Fixed Kickstart functionality.
- Reposync: Fixed URLGrabber error handling.
- Reposync: Fix modular data handling for cloned channels (bsc#1177508)

spacewalk-client-tools:

- Adapt to new SSL implementation of rhnlib (bsc#1181807)

spacewalk-proxy:

- Adapt to new SSL implementation of rhnlib (bsc#1181807)

spacewalk-proxy-installer:

- Adapt to new SSL implementation of rhnlib (bsc#1181807)

spacewalk-web:

- Replace CRLF in ssh priv key when bootstrapping (bsc#1182685)
- Upgrade immer to fix CVE-2020-28477
- Default to preferred items per page in content lifecycle lists
(bsc#1180558)
- Fix sorting in content lifecycle projects and cluster tables
(bsc#1180558)

How to apply this update: 1. Log in as root user to the SUSE Manager
proxy. 2. Stop the proxy service: spacewalk-proxy stop 3. Apply the patch
using either zypper patch or YaST Online Update. 4. Start the Spacewalk
service: spacewalk-proxy start

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:0906-1 to address this issue and obtain further details.

    CVEs related to QID 174822

    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:0906-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-March/008524.html