Oval Definition:oval:org.opensuse.security:def:100286
Revision Date:2021-06-02Version:1
Title: (Important)
Description:

This update for xstream fixes the following issues:

- Upgrade to 1.4.16 - CVE-2021-21351: remote attacker to load and execute arbitrary code (bsc#1184796) - CVE-2021-21349: SSRF can lead to a remote attacker to request data from internal resources (bsc#1184797) - CVE-2021-21350: arbitrary code execution (bsc#1184380) - CVE-2021-21348: remote attacker could cause denial of service by consuming maximum CPU time (bsc#1184374) - CVE-2021-21347: remote attacker to load and execute arbitrary code from a remote host (bsc#1184378) - CVE-2021-21344: remote attacker could load and execute arbitrary code from a remote host (bsc#1184375) - CVE-2021-21342: server-side forgery (bsc#1184379) - CVE-2021-21341: remote attacker could cause a denial of service by allocating 100% CPU time (bsc#1184377) - CVE-2021-21346: remote attacker could load and execute arbitrary code (bsc#1184373) - CVE-2021-21345: remote attacker with sufficient rights could execute commands (bsc#1184372) - CVE-2021-21343: replace or inject objects, that result in the deletion of files on the local host (bsc#1184376)
Family:unixClass:patch
Status:Reference(s):1164572
1164574
1184372
1184373
1184374
1184375
1184376
1184377
1184378
1184379
1184380
1184796
1184797
CVE-2020-9272
CVE-2020-9273
CVE-2021-21341
CVE-2021-21342
CVE-2021-21343
CVE-2021-21344
CVE-2021-21345
CVE-2021-21346
CVE-2021-21347
CVE-2021-21348
CVE-2021-21349
CVE-2021-21350
CVE-2021-21351
openSUSE-SU-2020:0273-1
Platform(s):Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
SUSE Package Hub for SUSE Linux Enterprise 15 SP1
Product(s):
Definition Synopsis
  • Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM is installed
  • AND xstream-1.4.16-3.8.1 is installed
  • Definition Synopsis
  • SUSE Package Hub for SUSE Linux Enterprise 15 SP1 is installed
  • AND Package Information
  • proftpd-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-devel-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-doc-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-lang-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-ldap-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-mysql-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-pgsql-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-radius-1.3.6c-bp151.4.9.1 is installed
  • OR proftpd-sqlite-1.3.6c-bp151.4.9.1 is installed
  • BACK