Revision Date: | 2021-01-20 | Version: | 1 |
Title: | (Important) |
Description: |
This update for xstream fixes the following issues:
xstream was updated to version 1.4.15.
- CVE-2020-26217: Fixed a remote code execution due to insecure XML deserialization when relying on blocklists (bsc#1180994). - CVE-2020-26258: Fixed a server-side request forgery vulnerability (bsc#1180146). - CVE-2020-26259: Fixed an arbitrary file deletion vulnerability (bsc#1180145).
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1180145 1180146 1180994 CVE-2018-16391 CVE-2018-16392 CVE-2018-16393 CVE-2018-16418 CVE-2018-16419 CVE-2018-16420 CVE-2018-16421 CVE-2018-16422 CVE-2018-16423 CVE-2018-16424 CVE-2018-16425 CVE-2018-16426 CVE-2018-16427 CVE-2020-26217 CVE-2020-26258 CVE-2020-26259
|
Platform(s): | Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE SUSE Linux Enterprise Desktop 15 SP2 SUSE Linux Enterprise High Performance Computing 15 SP2 SUSE Linux Enterprise Module for Basesystem 15 SP2 SUSE Linux Enterprise Server 15 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.1 SUSE Manager Server 4.1
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed AND opensc-0.19.0-1.14 is installed
|
Definition Synopsis |
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE is installed
AND xstream-1.4.15-3.3.2 is installed
|