gpp_maybe Security update for smt
slesmtsp3-smt-13798


This update for smt to 2.0.34 fixes the following issues: These security issues were fixed: - CVE-2018-12471: Xml External Entity processing in the RegistrationSharing modules allowed to read arbitrary file read (bsc#1103809) - CVE-2018-12470: SQL injection in RegistrationSharing module allows remote attackers to run arbitary SQL statements (bsc#1103810) - CVE-2018-12472: Authentication bypass in sibling check facilitated further attacks on SMT (bsc#1104076) SUSE would like to thank Jake Miller for reporting these issues to us. This non-security issue was fixed: - More verbose incomplete registration logging (bsc#1072921, bsc#1074608)


cloud_download Downloads

SUSE Linux Enterprise Subscription Management Tool 11.3 unknown
  • Packages
    res-signingkeys
    Signing Key for RES
    2.0.34-50.8.1 lock rpm
    smt
    Subscription Management Tool
    2.0.34-50.8.1 lock rpm lock src
    smt-support
    SMT support proxy
    2.0.34-50.8.1 lock rpm
SUSE Linux Enterprise Subscription Management Tool 11.3 unknown
  • Packages
    res-signingkeys
    Signing Key for RES
    2.0.34-50.8.1 lock rpm
    smt
    Subscription Management Tool
    2.0.34-50.8.1 lock rpm lock src
    smt-support
    SMT support proxy
    2.0.34-50.8.1 lock rpm
SUSE Linux Enterprise Subscription Management Tool 11.3 unknown
  • Packages
    res-signingkeys
    Signing Key for RES
    2.0.34-50.8.1 lock rpm
    smt
    Subscription Management Tool
    2.0.34-50.8.1 lock rpm lock src
    smt-support
    SMT support proxy
    2.0.34-50.8.1 lock rpm