Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in spacewalk
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in spacewalk
ID: SUSE-SU-2013:0841-1
Distribution: SUSE
Plattformen: SUSE Manager 1.2 for SLE 11 SP1, SUSE Manager 1.7 for SLE 11 SP2
Datum: Di, 28. Mai 2013, 23:04
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2056
Applikationen: Spacewalk

Originalnachricht

   SUSE Security Update: Security update for SUSE Manager
______________________________________________________________________________

Announcement ID: SUSE-SU-2013:0841-1
Rating: important
References: #819365
Cross-References: CVE-2013-2056
Affected Products:
SUSE Manager 1.7 for SLE 11 SP2
SUSE Manager 1.2 for SLE 11 SP1
______________________________________________________________________________

An update that fixes one vulnerability is now available. It
includes one version update.

Description:


spacewalk-backend has been updated to fix an authentication
checking problem. (bnc#819365, CVE-2013-2056)

Security Issue reference:

* CVE-2013-2056
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2056
>


Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- SUSE Manager 1.7 for SLE 11 SP2:

zypper in -t patch sleman17sp2-spacewalk-backend-7746

- SUSE Manager 1.2 for SLE 11 SP1:

zypper in -t patch sleman12sp1-spacewalk-backend-7748

To bring your system up-to-date, use "zypper patch".


Package List:

- SUSE Manager 1.7 for SLE 11 SP2 (x86_64) [New Version: 1.7.38.24]:

spacewalk-backend-1.7.38.24-0.7.1
spacewalk-backend-app-1.7.38.24-0.7.1
spacewalk-backend-applet-1.7.38.24-0.7.1
spacewalk-backend-config-files-1.7.38.24-0.7.1
spacewalk-backend-config-files-common-1.7.38.24-0.7.1
spacewalk-backend-config-files-tool-1.7.38.24-0.7.1
spacewalk-backend-iss-1.7.38.24-0.7.1
spacewalk-backend-iss-export-1.7.38.24-0.7.1
spacewalk-backend-libs-1.7.38.24-0.7.1
spacewalk-backend-package-push-server-1.7.38.24-0.7.1
spacewalk-backend-server-1.7.38.24-0.7.1
spacewalk-backend-sql-1.7.38.24-0.7.1
spacewalk-backend-sql-oracle-1.7.38.24-0.7.1
spacewalk-backend-sql-postgresql-1.7.38.24-0.7.1
spacewalk-backend-tools-1.7.38.24-0.7.1
spacewalk-backend-xml-export-libs-1.7.38.24-0.7.1
spacewalk-backend-xmlrpc-1.7.38.24-0.7.1
spacewalk-backend-xp-1.7.38.24-0.7.1

- SUSE Manager 1.2 for SLE 11 SP1 (x86_64):

spacewalk-backend-1.2.74-0.60.1
spacewalk-backend-app-1.2.74-0.60.1
spacewalk-backend-applet-1.2.74-0.60.1
spacewalk-backend-config-files-1.2.74-0.60.1
spacewalk-backend-config-files-common-1.2.74-0.60.1
spacewalk-backend-config-files-tool-1.2.74-0.60.1
spacewalk-backend-iss-1.2.74-0.60.1
spacewalk-backend-iss-export-1.2.74-0.60.1
spacewalk-backend-libs-1.2.74-0.60.1
spacewalk-backend-package-push-server-1.2.74-0.60.1
spacewalk-backend-server-1.2.74-0.60.1
spacewalk-backend-sql-1.2.74-0.60.1
spacewalk-backend-sql-oracle-1.2.74-0.60.1
spacewalk-backend-tools-1.2.74-0.60.1
spacewalk-backend-xml-export-libs-1.2.74-0.60.1
spacewalk-backend-xmlrpc-1.2.74-0.60.1
spacewalk-backend-xp-1.2.74-0.60.1


References:

http://support.novell.com/security/cve/CVE-2013-2056.html
https://bugzilla.novell.com/819365
?keywords=26e847ac77c8ff404f27e1077a152dfb
?keywords=8e4d137510d878e6c1ce78859fc5f7b0

--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung