gpp_maybe
Security update for supportutils
SUSE-SLE-Module-Basesystem-15-2019-480
This update for supportutils fixes the following issues: Security issues fixed: - CVE-2018-19640: Fixed an issue where users could kill arbitrary processes (bsc#1118463). - CVE-2018-19638: Fixed an issue where users could overwrite arbitrary log files (bsc#1118460). - CVE-2018-19639: Fixed a code execution if run with -v (bsc#1118462). - CVE-2018-19637: Fixed an issue where static temporary filename could allow overwriting of files (bsc#1117776). Other issues fixed: - Fixed invalid exit code commands (bsc#1125666). - Included additional SUSE separation (bsc#1125609). - Merged added listing of locked packes by zypper. - Exclude pam.txt per GDPR by default (bsc#1112461). - Clarified -x functionality in supportconfig(8) (bsc#1115245). - udev service and provide the whole journal content in supportconfig (bsc#1051797). - supportconfig collects tuned profile settings (bsc#1071545). - sfdisk -d no disk device specified (bsc#1043311). - Added vulnerabilites status check in basic-health.txt (bsc#1105849). - Added only sched_domain from cpu0. - Blacklist sched_domain from proc.txt (bsc#1046681). - Added firewall-cmd info. - Add ls -lA --time-style=long-iso /etc/products.d/ - Dump lsof errors. - Added corosync status to ha_info. - Dump find errors in ib_info.
-
Release DateFeb 25 2019
-
ReferencesBugzilla: 1125666, 1043311, 1051797, 1046681, 1115245, 1118462, 1118463, 1071545, 1117776, 1105849, 1112461, 1125609, 1118460
CVEs: CVE-2018-19640, CVE-2018-19638, CVE-2018-19637, CVE-2018-19639 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15 aarch64
-
Packages
Basesystem Module 15 s390x
-
Packages
Basesystem Module 15 ppc64le
-
Packages
Basesystem Module 15 x86_64
-
Packages