SUSE Updates
2509Warning Date
Severity Level
Warning Number
Target Sector
12 April, 2020
● Medium
2020-1128
All
Description:
SUSE has released security updates to address multiple vulnerabilities in the following product:
- djvulibre
- SUSE Linux Enterprise Software Development Kit 12-SP5
- SUSE Linux Enterprise Software Development Kit 12-SP4
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Server 12-SP4
- permissions
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- libssh
- SUSE Linux Enterprise Software Development Kit 12-SP5
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- ceph
- SUSE Linux Enterprise Software Development Kit 12-SP5
- SUSE Linux Enterprise Software Development Kit 12-SP4
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Server 12-SP4
- SUSE Enterprise Storage 5
- python-PyYAML
- SUSE Linux Enterprise Module for Python2 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- mgetty
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- vino
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Server 12-SP4
- rubygem-actionview-4_2
- SUSE OpenStack Cloud Crowbar 9
- SUSE OpenStack Cloud Crowbar 8
- SUSE OpenStack Cloud 7djvulibre
- SUSE Linux Enterprise Software Development Kit 12-SP5
- SUSE Linux Enterprise Software Development Kit 12-SP4
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Server 12-SP4
- permissions
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- libssh
- SUSE Linux Enterprise Software Development Kit 12-SP5
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- ceph
- SUSE Linux Enterprise Software Development Kit 12-SP5
- SUSE Linux Enterprise Software Development Kit 12-SP4
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Server 12-SP4
- SUSE Enterprise Storage 5
- python-PyYAML
- SUSE Linux Enterprise Module for Python2 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- mgetty
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP1
- vino
- SUSE Linux Enterprise Server 12-SP5
- SUSE Linux Enterprise Server 12-SP4
- rubygem-actionview-4_2
- SUSE OpenStack Cloud Crowbar 9
- SUSE OpenStack Cloud Crowbar 8
- SUSE OpenStack Cloud 7
Threats:
- Execute arbitrary code
- Denial of Service )DoS)
Best practice and Recommendations:
The CERT team encourages users to apply the necessary updates according to the links below:
- https://www.suse.com/support/update/announcement/2020/suse-su-20200970-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200969-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200968-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200967-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200962-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200959-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200957-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200955-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200954-1/