SUSE-SU-2012:0254-1: moderate: Security update for SUSE Manager
    sle-updates at lists.suse.com 
    sle-updates at lists.suse.com
       
    Thu Feb  9 16:08:54 MST 2012
    
    
  
   SUSE Security Update: Security update for SUSE Manager
______________________________________________________________________________
Announcement ID:    SUSE-SU-2012:0254-1
Rating:             moderate
References:         #728894 #730408 #731304 #732517 #732845 #734164 
                    #736240 #737649 #738054 #740813 #742145 
Cross-References:   CVE-2012-0059
Affected Products:
                    SUSE Manager 1.2 for SLE 11 SP1
______________________________________________________________________________
   An update that solves one vulnerability and has 10 fixes is
   now available.
Description:
   This 2012/01 Update for SUSE Manager provides the following
   security fixes:
   * CVE-2012-0059: The spacewalk admin was able to read
   the password of other users that failed to register. The
   password is even send via email in plaintext.
   In addition the following non-security changes were added:
   * 728894: Fix internal server error when deleting a
   software channel
   * 730408: Remove markup from error message
   * 731304: Fix display of XML snippets in the web ui
   * 732517: Remove confirmation dialog when adding a
   channel
   * 732845: Fix query to determine config channels in SSM
   * 734164: Make all chars display properly
   * 736240: Remove setuid bits from oracle binaries
   * 737649: Add missing URL to auditlog configuration
   * 738054: Offer to disable YAST Automatic Online Update
   if it is enabled on the client.
   * 740813: Fix mgr-ncc-sync -s resetting the max_members
   of system groups to 10
   * 742145: Set up seclist in registration.py
   How to apply this update:
   1. Log in as root user to the SUSE Manager server. 2.
   Stop the Spacewalk service: spacewalk-service stop 3. Apply
   the patch using either zypper patch or YaST Online Update.
   4. Optionally install new packages (required only if audit
   logging should be enabled): zypper in auditlog-keeper
   auditlog-keeper-spacewalk-validator auditlog-keeper-syslog
   Additional output plugins available: auditlog-keeper-rdbms,
   auditlog-keeper-xmlout To enable audit logging add the
   following line to /etc/rhn/rhn.conf: audit.enabled = 1 5.
   Start the Spacewalk service: spacewalk-service start
   Security Issue reference:
   * CVE-2012-0059
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0059
   >
Indications:
   Please update.
Patch Instructions:
   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:
   - SUSE Manager 1.2 for SLE 11 SP1:
      zypper in -t patch sleman12sp1-susemanager-201201-5718
   To bring your system up-to-date, use "zypper patch".
Package List:
   - SUSE Manager 1.2 for SLE 11 SP1 (x86_64):
      spacewalk-backend-1.2.74-0.46.1
      spacewalk-backend-app-1.2.74-0.46.1
      spacewalk-backend-applet-1.2.74-0.46.1
      spacewalk-backend-config-files-1.2.74-0.46.1
      spacewalk-backend-config-files-common-1.2.74-0.46.1
      spacewalk-backend-config-files-tool-1.2.74-0.46.1
      spacewalk-backend-iss-1.2.74-0.46.1
      spacewalk-backend-iss-export-1.2.74-0.46.1
      spacewalk-backend-libs-1.2.74-0.46.1
      spacewalk-backend-package-push-server-1.2.74-0.46.1
      spacewalk-backend-server-1.2.74-0.46.1
      spacewalk-backend-sql-1.2.74-0.46.1
      spacewalk-backend-sql-oracle-1.2.74-0.46.1
      spacewalk-backend-tools-1.2.74-0.46.1
      spacewalk-backend-xml-export-libs-1.2.74-0.46.1
      spacewalk-backend-xmlrpc-1.2.74-0.46.1
      spacewalk-backend-xp-1.2.74-0.46.1
      susemanager-1.2.0-0.50.1
      susemanager-tools-1.2.0-0.50.1
   - SUSE Manager 1.2 for SLE 11 SP1 (noarch):
      editarea-0.8.2-0.4.1
      spacewalk-base-1.2.31-0.33.1
      spacewalk-base-minimal-1.2.31-0.33.1
      spacewalk-certs-tools-1.2.2-0.24.1
      spacewalk-grail-1.2.31-0.33.1
      spacewalk-html-1.2.31-0.33.1
      spacewalk-java-1.2.115-0.52.1
      spacewalk-java-config-1.2.115-0.52.1
      spacewalk-java-lib-1.2.115-0.52.1
      spacewalk-java-oracle-1.2.115-0.52.1
      spacewalk-pxt-1.2.31-0.33.1
      spacewalk-sniglets-1.2.31-0.33.1
      spacewalk-taskomatic-1.2.115-0.52.1
References:
   http://support.novell.com/security/cve/CVE-2012-0059.html
   https://bugzilla.novell.com/728894
   https://bugzilla.novell.com/730408
   https://bugzilla.novell.com/731304
   https://bugzilla.novell.com/732517
   https://bugzilla.novell.com/732845
   https://bugzilla.novell.com/734164
   https://bugzilla.novell.com/736240
   https://bugzilla.novell.com/737649
   https://bugzilla.novell.com/738054
   https://bugzilla.novell.com/740813
   https://bugzilla.novell.com/742145
   http://download.novell.com/patch/finder/?keywords=cbd90cc906d52950a552c6ddd2659abf
    
    
More information about the sle-updates
mailing list