SUSE-SU-2018:3815-1: important: Security update for salt

sle-updates at lists.suse.com sle-updates at lists.suse.com
Tue Nov 20 07:08:42 MST 2018


   SUSE Security Update: Security update for salt
______________________________________________________________________________

Announcement ID:    SUSE-SU-2018:3815-1
Rating:             important
References:         #1110938 #1113698 #1113699 #1113784 #1114197 
                    
Cross-References:   CVE-2018-15750 CVE-2018-15751
Affected Products:
                    SUSE Linux Enterprise Module for Server Applications 15
                    SUSE Linux Enterprise Module for Basesystem 15
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:

   This update for salt fixes the following issues:

   Security issues fixed:

   - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api
     (bsc#1113698).
   - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi)
     that allows to execute arbitrary commands (bsc#1113699).

   Non-security issues fixed:

   - Improved handling of LDAP group id. gid is no longer treated as a
     string, which could have lead to faulty group creations (bsc#1113784).
   - Fixed async call to process manager (bsc#1110938).
   - Fixed OS arch detection when RPM is not installed (bsc#1114197).


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Module for Server Applications 15:

      zypper in -t patch SUSE-SLE-Module-Server-Applications-15-2018-2713=1

   - SUSE Linux Enterprise Module for Basesystem 15:

      zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-2713=1



Package List:

   - SUSE Linux Enterprise Module for Server Applications 15 (aarch64 ppc64le s390x x86_64):

      salt-api-2018.3.0-5.20.1
      salt-cloud-2018.3.0-5.20.1
      salt-master-2018.3.0-5.20.1
      salt-proxy-2018.3.0-5.20.1
      salt-ssh-2018.3.0-5.20.1
      salt-syndic-2018.3.0-5.20.1

   - SUSE Linux Enterprise Module for Server Applications 15 (noarch):

      salt-fish-completion-2018.3.0-5.20.1

   - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64):

      python2-salt-2018.3.0-5.20.1
      python3-salt-2018.3.0-5.20.1
      salt-2018.3.0-5.20.1
      salt-doc-2018.3.0-5.20.1
      salt-minion-2018.3.0-5.20.1

   - SUSE Linux Enterprise Module for Basesystem 15 (noarch):

      salt-bash-completion-2018.3.0-5.20.1
      salt-zsh-completion-2018.3.0-5.20.1


References:

   https://www.suse.com/security/cve/CVE-2018-15750.html
   https://www.suse.com/security/cve/CVE-2018-15751.html
   https://bugzilla.suse.com/1110938
   https://bugzilla.suse.com/1113698
   https://bugzilla.suse.com/1113699
   https://bugzilla.suse.com/1113784
   https://bugzilla.suse.com/1114197



More information about the sle-updates mailing list