SUSE Updates
3033Warning Date
Severity Level
Warning Number
Target Sector
30 August, 2020
● High
2020-1697
All
Description:
SUSE has released security updates to address multiple vulnerabilities in the following products:
- SUSE Linux Enterprise Module for SUSE Manager Server 4.1
- SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1
- postgresql10
- SUSE Linux Enterprise Module for Server Applications 15-SP2
- SUSE Linux Enterprise Module for Server Applications 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP2
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- libqt5-qtbase
- SUSE Linux Enterprise Module for Desktop Applications 15-SP2
- SUSE Linux Enterprise Module for Basesystem 15-SP2
- openvpn-openssl1
- SUSE Linux Enterprise Server 11-SECURITY
- openvpn
- SUSE Linux Enterprise Server 12-SP5
- targetcli-fb
- SUSE Linux Enterprise Server 12-SP5
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Unauthorized disclosure of information.
- SQL injection.
- Arbitrary code execution.
Best practice and Recommendations:
The CERT team encourages users to review SUSE security advisory and apply the necessary updates:
- https://www.suse.com/support/update/announcement/2020/suse-su-20202355-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20202357-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-202014468-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20202359-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20202360-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20202373-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20202373-1/