SUSE-SU-2018:3815-1: important: Security update for salt
    sle-security-updates at lists.suse.com 
    sle-security-updates at lists.suse.com
       
    Tue Nov 20 07:08:42 MST 2018
    
    
  
   SUSE Security Update: Security update for salt
______________________________________________________________________________
Announcement ID:    SUSE-SU-2018:3815-1
Rating:             important
References:         #1110938 #1113698 #1113699 #1113784 #1114197 
                    
Cross-References:   CVE-2018-15750 CVE-2018-15751
Affected Products:
                    SUSE Linux Enterprise Module for Server Applications 15
                    SUSE Linux Enterprise Module for Basesystem 15
______________________________________________________________________________
   An update that solves two vulnerabilities and has three
   fixes is now available.
Description:
   This update for salt fixes the following issues:
   Security issues fixed:
   - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api
     (bsc#1113698).
   - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi)
     that allows to execute arbitrary commands (bsc#1113699).
   Non-security issues fixed:
   - Improved handling of LDAP group id. gid is no longer treated as a
     string, which could have lead to faulty group creations (bsc#1113784).
   - Fixed async call to process manager (bsc#1110938).
   - Fixed OS arch detection when RPM is not installed (bsc#1114197).
Patch Instructions:
   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:
   - SUSE Linux Enterprise Module for Server Applications 15:
      zypper in -t patch SUSE-SLE-Module-Server-Applications-15-2018-2713=1
   - SUSE Linux Enterprise Module for Basesystem 15:
      zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-2713=1
Package List:
   - SUSE Linux Enterprise Module for Server Applications 15 (aarch64 ppc64le s390x x86_64):
      salt-api-2018.3.0-5.20.1
      salt-cloud-2018.3.0-5.20.1
      salt-master-2018.3.0-5.20.1
      salt-proxy-2018.3.0-5.20.1
      salt-ssh-2018.3.0-5.20.1
      salt-syndic-2018.3.0-5.20.1
   - SUSE Linux Enterprise Module for Server Applications 15 (noarch):
      salt-fish-completion-2018.3.0-5.20.1
   - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64):
      python2-salt-2018.3.0-5.20.1
      python3-salt-2018.3.0-5.20.1
      salt-2018.3.0-5.20.1
      salt-doc-2018.3.0-5.20.1
      salt-minion-2018.3.0-5.20.1
   - SUSE Linux Enterprise Module for Basesystem 15 (noarch):
      salt-bash-completion-2018.3.0-5.20.1
      salt-zsh-completion-2018.3.0-5.20.1
References:
   https://www.suse.com/security/cve/CVE-2018-15750.html
   https://www.suse.com/security/cve/CVE-2018-15751.html
   https://bugzilla.suse.com/1110938
   https://bugzilla.suse.com/1113698
   https://bugzilla.suse.com/1113699
   https://bugzilla.suse.com/1113784
   https://bugzilla.suse.com/1114197
    
    
More information about the sle-security-updates
mailing list