gpp_maybe
Security update for smt
slesmtsp3-smt-13798
This update for smt to 2.0.34 fixes the following issues: These security issues were fixed: - CVE-2018-12471: Xml External Entity processing in the RegistrationSharing modules allowed to read arbitrary file read (bsc#1103809) - CVE-2018-12470: SQL injection in RegistrationSharing module allows remote attackers to run arbitary SQL statements (bsc#1103810) - CVE-2018-12472: Authentication bypass in sibling check facilitated further attacks on SMT (bsc#1104076) SUSE would like to thank Jake Miller for reporting these issues to us. This non-security issue was fixed: - More verbose incomplete registration logging (bsc#1072921, bsc#1074608)
-
Release DateSep 27 2018
-
ReferencesBugzilla: 1074608, 1104076, 1072921, 1103809, 1103810
CVEs: CVE-2018-12472, CVE-2018-12470, CVE-2018-12471 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Subscription Management Tool 11.3 unknown
-
Packagesres-signingkeys
Signing Key for RESsmt2.0.34-50.8.1 lock rpm
Subscription Management Toolsmt-support2.0.34-50.8.1 lock rpm lock src
SMT support proxy2.0.34-50.8.1 lock rpm
SUSE Linux Enterprise Subscription Management Tool 11.3 unknown
-
Packagesres-signingkeys
Signing Key for RESsmt2.0.34-50.8.1 lock rpm
Subscription Management Toolsmt-support2.0.34-50.8.1 lock rpm lock src
SMT support proxy2.0.34-50.8.1 lock rpm
SUSE Linux Enterprise Subscription Management Tool 11.3 unknown
-
Packagesres-signingkeys
Signing Key for RESsmt2.0.34-50.8.1 lock rpm
Subscription Management Toolsmt-support2.0.34-50.8.1 lock rpm lock src
SMT support proxy2.0.34-50.8.1 lock rpm