Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in couchdb
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in couchdb
ID: SUSE-SU-2018:2765-1
Distribution: SUSE
Plattformen: SUSE OpenStack Cloud Crowbar 8
Datum: Do, 20. September 2018, 16:01
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8007
Applikationen: CouchDB

Originalnachricht

   SUSE Security Update: Security update for couchdb
______________________________________________________________________________

Announcement ID: SUSE-SU-2018:2765-1
Rating: moderate
References: #1100973
Cross-References: CVE-2018-8007
Affected Products:
SUSE OpenStack Cloud Crowbar 8
______________________________________________________________________________

An update that fixes one vulnerability is now available.

Description:

This update for couchdb fixes the following security issues:

- CVE-2018-8007: Apache CouchDB administrative users can configure the
database server via HTTP(S). Due to insufficient validation of
administrator-supplied configuration settings via the HTTP API, it was
possible for a CouchDB administrator user to escalate their privileges
to that of the operating system's user that CouchDB runs under, by
bypassing the blacklist of configuration settings that are not allowed
to be modified via the HTTP API (bsc#1100973)


Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation
methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- SUSE OpenStack Cloud Crowbar 8:

zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2018-1930=1



Package List:

- SUSE OpenStack Cloud Crowbar 8 (x86_64):

couchdb-1.7.2-3.3.1
couchdb-debuginfo-1.7.2-3.3.1
couchdb-debugsource-1.7.2-3.3.1


References:

https://www.suse.com/security/cve/CVE-2018-8007.html
https://bugzilla.suse.com/1100973

_______________________________________________
sle-security-updates mailing list
sle-security-updates@lists.suse.com
http://lists.suse.com/mailman/listinfo/sle-security-updates
Pro-Linux
Unterstützer werden
Neue Nachrichten
Werbung