QID 750094

QID 750094: SUSE Enterprise Linux Security Update for xstream (SUSE-SU-2021:1840-1)

This update for xstream fixes the following issues: - upgrade to 1.4.16 - cve-2021-21351: remote attacker to load and execute arbitrary code (bsc#1184796) - cve-2021-21349: ssrf can lead to a remote attacker to request data from internal resources (bsc#1184797) - cve-2021-21350: arbitrary code execution (bsc#1184380) - cve-2021-21348: remote attacker could cause denial of service by consuming maximum cpu time (bsc#1184374) - cve-2021-21347: remote attacker to load and execute arbitrary code from a remote host (bsc#1184378) - cve-2021-21344: remote attacker could load and execute arbitrary code from a remote host (bsc#1184375) - cve-2021-21342: server-side forgery (bsc#1184379) - cve-2021-21341: remote attacker could cause a denial of service by allocating 100% cpu time (bsc#1184377) - cve-2021-21346: remote attacker could load and execute arbitrary code (bsc#1184373) - cve-2021-21345: remote attacker with sufficient rights could execute commands (bsc#1184372) - cve-2021-21343: replace or inject objects, that result in the deletion of files on the local host (bsc#1184376)

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as Critical - 9.9 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:1840-1 to address this issue and obtain further details.
    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:1840-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-June/008912.html