Revision Date: | 2021-06-02 | Version: | 1 |
Title: | Security update for xstream (Important) |
Description: |
This update for xstream fixes the following issues:
- Upgrade to 1.4.16 - CVE-2021-21351: remote attacker to load and execute arbitrary code (bsc#1184796) - CVE-2021-21349: SSRF can lead to a remote attacker to request data from internal resources (bsc#1184797) - CVE-2021-21350: arbitrary code execution (bsc#1184380) - CVE-2021-21348: remote attacker could cause denial of service by consuming maximum CPU time (bsc#1184374) - CVE-2021-21347: remote attacker to load and execute arbitrary code from a remote host (bsc#1184378) - CVE-2021-21344: remote attacker could load and execute arbitrary code from a remote host (bsc#1184375) - CVE-2021-21342: server-side forgery (bsc#1184379) - CVE-2021-21341: remote attacker could cause a denial of service by allocating 100% CPU time (bsc#1184377) - CVE-2021-21346: remote attacker could load and execute arbitrary code (bsc#1184373) - CVE-2021-21345: remote attacker with sufficient rights could execute commands (bsc#1184372) - CVE-2021-21343: replace or inject objects, that result in the deletion of files on the local host (bsc#1184376)
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1058115 1071995 1131644 1131868 1131870 1131871 1131872 1131874 1133640 1138529 1144443 1144524 1146848 1150934 1152856 1154212 1154366 1156015 1156920 1157465 1159284 1160594 1160764 1160850 1160888 1160968 1161335 1161779 1162327 1163922 1165572 1165629 1165631 1166847 1166933 1167331 1167437 1168340 1169604 1169800 1170104 1170288 1170595 1171701 1171906 1171988 1172075 1172428 1173072 1173798 1174165 1174205 1174757 1174955 1175112 1175122 1175128 1175204 1175213 1175239 1175476 1175515 1175518 1175568 1175674 1175691 1175992 1176069 1176625 1177155 1184372 1184373 1184374 1184375 1184376 1184377 1184378 1184379 1184380 1184796 1184797 930077 930078 930079 CVE-2015-4141 CVE-2015-4142 CVE-2015-4143 CVE-2015-8041 CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 CVE-2018-14526 CVE-2019-11555 CVE-2019-13377 CVE-2019-13456 CVE-2019-14562 CVE-2019-14902 CVE-2019-14907 CVE-2019-16275 CVE-2019-17185 CVE-2019-18897 CVE-2019-2894 CVE-2019-2933 CVE-2019-2945 CVE-2019-2949 CVE-2019-2958 CVE-2019-2962 CVE-2019-2964 CVE-2019-2973 CVE-2019-2975 CVE-2019-2978 CVE-2019-2981 CVE-2019-2983 CVE-2019-2987 CVE-2019-2988 CVE-2019-2989 CVE-2019-2992 CVE-2019-2999 CVE-2019-3688 CVE-2019-3690 CVE-2019-5068 CVE-2019-9494 CVE-2019-9495 CVE-2019-9497 CVE-2019-9498 CVE-2019-9499 CVE-2020-10135 CVE-2020-10135 CVE-2020-11651 CVE-2020-11652 CVE-2020-14314 CVE-2020-14314 CVE-2020-14331 CVE-2020-14331 CVE-2020-14356 CVE-2020-14356 CVE-2020-14363 CVE-2020-14386 CVE-2020-14386 CVE-2020-15708 CVE-2020-16166 CVE-2020-16166 CVE-2020-1749 CVE-2020-1749 CVE-2020-24394 CVE-2020-24394 CVE-2020-25637 CVE-2020-2583 CVE-2020-2590 CVE-2020-2593 CVE-2020-2601 CVE-2020-2604 CVE-2020-2654 CVE-2020-2659 CVE-2020-8013 CVE-2020-8027 CVE-2021-21341 CVE-2021-21342 CVE-2021-21343 CVE-2021-21344 CVE-2021-21345 CVE-2021-21346 CVE-2021-21347 CVE-2021-21348 CVE-2021-21349 CVE-2021-21350 CVE-2021-21351 SUSE-SU-2019:3238-1 SUSE-SU-2020:0111-2 SUSE-SU-2020:0224-1 SUSE-SU-2020:0231-1 SUSE-SU-2020:1023-1 SUSE-SU-2020:1163-1 SUSE-SU-2020:1973-1 SUSE-SU-2020:2474-2 SUSE-SU-2020:2610-1 SUSE-SU-2020:2712-2 SUSE-SU-2020:2713-1 SUSE-SU-2020:2814-1 SUSE-SU-2020:2969-1 SUSE-SU-2020:3380-1 SUSE-SU-2021:1840-1
Platform(s): | SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5 SUSE Linux Enterprise Build System Kit 12 SUSE Linux Enterprise Build System Kit 12 SP1 SUSE Linux Enterprise Build System Kit 12 SP2 SUSE Linux Enterprise Build System Kit 12 SP3 SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Desktop 12 SP1 SUSE Linux Enterprise Desktop 12 SP2 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Desktop 12 SP4 SUSE Linux Enterprise Desktop 15 SP3 SUSE Linux Enterprise for SAP 12 SUSE Linux Enterprise High Availability 12 SP4 SUSE Linux Enterprise High Performance Computing 15 SP3 SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise Module for additional PackageHub packages 15 SUSE Linux Enterprise Module for additional PackageHub packages 15 SP1 SUSE Linux Enterprise Module for Development Tools 15 SP3 SUSE Linux Enterprise Module for Public Cloud 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2-LTSS SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Server 11 SP3-LTSS SUSE Linux Enterprise Server 11 SP4 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12-LTSS SUSE Linux Enterprise Server 15 SP3 SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SUSE Linux Enterprise Server for SAP Applications 15 SP3 SUSE Linux Enterprise Server for VMWare 11 SP2 SUSE Linux Enterprise Server for VMWare 11 SP3 SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise Software Development Kit 12 SUSE Linux Enterprise Software Development Kit 12 SP1 SUSE Linux Enterprise Software Development Kit 12 SP2 SUSE Linux Enterprise Workstation Extension 12 SUSE Linux Enterprise Workstation Extension 12 SP1 SUSE Linux Enterprise Workstation Extension 15 SUSE Linux Enterprise Workstation Extension 15 SP1 SUSE Linux Enterprise Workstation Extension 15 SP2 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 SUSE OpenStack Cloud 5
| Product(s): | |
Definition Synopsis |
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5 is installed AND Package Information
openstack-neutron-2014.2.2.dev26-3 is installed
OR openstack-neutron-dhcp-agent-2014.2.2.dev26-3 is installed
OR openstack-neutron-ha-tool-2014.2.2.dev26-3 is installed
OR openstack-neutron-l3-agent-2014.2.2.dev26-3 is installed
OR openstack-neutron-lbaas-agent-2014.2.2.dev26-3 is installed
OR openstack-neutron-linuxbridge-agent-2014.2.2.dev26-3 is installed
OR openstack-neutron-metadata-agent-2014.2.2.dev26-3 is installed
OR openstack-neutron-metering-agent-2014.2.2.dev26-3 is installed
OR openstack-neutron-openvswitch-agent-2014.2.2.dev26-3 is installed
OR openstack-neutron-vpn-agent-2014.2.2.dev26-3 is installed
OR python-neutron-2014.2.2.dev26-3 is installed
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 is installed
AND Package Information
cups-1.7.5-9 is installed
OR cups-ddk-1.7.5-9 is installed
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 SP1 is installed
AND Package Information
krb5-mini-1.12.1-22 is installed
OR krb5-mini-devel-1.12.1-22 is installed
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 SP2 is installed
AND Package Information
libudev-mini-devel-228-150.7 is installed
OR libudev-mini1-228-150.7 is installed
OR systemd-mini-228-150.7 is installed
OR systemd-mini-devel-228-150.7 is installed
OR udev-mini-228-150.7 is installed
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 SP3 is installed
AND kernel-zfcpdump-4.4.82-6.3 is installed
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 is installed
AND Package Information
cron-4.2-55 is installed
OR cronie-1.4.11-55 is installed
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP1 is installed
AND Package Information
cups-filters-1.0.58-8 is installed
OR cups-filters-cups-browsed-1.0.58-8 is installed
OR cups-filters-foomatic-rip-1.0.58-8 is installed
OR cups-filters-ghostscript-1.0.58-8 is installed
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP2 is installed
AND Package Information
DirectFB-1.7.1-6 is installed
OR lib++dfb-1_7-1-1.7.1-6 is installed
OR libdirectfb-1_7-1-1.7.1-6 is installed
OR libdirectfb-1_7-1-32bit-1.7.1-6 is installed
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed
AND Package Information
MozillaFirefox-52.2.0esr-108 is installed
OR MozillaFirefox-translations-52.2.0esr-108 is installed
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP4 is installed
AND binutils-2.31-9.26 is installed
Definition Synopsis |
SUSE Linux Enterprise Module for Development Tools 15 SP3 is installed
AND xstream-1.4.16-3.8.1 is installed
Definition Synopsis |
SUSE Linux Enterprise for SAP 12 is installed
AND Package Information
kernel-default-3.12.61-52.80.1 is installed
OR kernel-default-base-3.12.61-52.80.1 is installed
OR kernel-default-devel-3.12.61-52.80.1 is installed
OR kernel-devel-3.12.61-52.80.1 is installed
OR kernel-macros-3.12.61-52.80.1 is installed
OR kernel-source-3.12.61-52.80.1 is installed
OR kernel-syms-3.12.61-52.80.1 is installed
OR kernel-xen-3.12.61-52.80.1 is installed
OR kernel-xen-base-3.12.61-52.80.1 is installed
OR kernel-xen-devel-3.12.61-52.80.1 is installed
OR kgraft-patch-3_12_61-52_80-default-1-2.1 is installed
OR kgraft-patch-3_12_61-52_80-xen-1-2.1 is installed
OR kgraft-patch-SLE12_Update_23-1-2.1 is installed
Definition Synopsis |
SUSE Linux Enterprise High Availability 12 SP4 is installed
AND lighttpd-1.4.35-3 is installed
Definition Synopsis |
Release Information
SUSE Linux Enterprise High Performance Computing 15-ESPOS is installed
libX11-1.6.5-3.12 is installed
OR libX11-6-1.6.5-3.12 is installed
OR libX11-6-32bit-1.6.5-3.12 is installed
OR libX11-data-1.6.5-3.12 is installed
OR libX11-devel-1.6.5-3.12 is installed
OR libX11-xcb1-1.6.5-3.12 is installed
OR libX11-xcb1-32bit-1.6.5-3.12 is installed
OR Package Information
SUSE Linux Enterprise High Performance Computing 15-LTSS is installed
libX11-1.6.5-3.12 is installed
OR libX11-6-1.6.5-3.12 is installed
OR libX11-6-32bit-1.6.5-3.12 is installed
OR libX11-data-1.6.5-3.12 is installed
OR libX11-devel-1.6.5-3.12 is installed
OR libX11-xcb1-1.6.5-3.12 is installed
OR libX11-xcb1-32bit-1.6.5-3.12 is installed
Definition Synopsis |
SUSE Linux Enterprise Module for additional PackageHub packages 15 is installed
AND Package Information
java-1_8_0-openjdk- is installed
OR java-1_8_0-openjdk-javadoc- is installed
Definition Synopsis |
SUSE Linux Enterprise Module for additional PackageHub packages 15 SP1 is installed
AND Package Information
Mesa-18.3.2-34.9 is installed
OR libOSMesa8-32bit-18.3.2-34.9 is installed
Definition Synopsis |
SUSE Linux Enterprise Module for Public Cloud 12 is installed
AND Package Information
kernel-ec2-3.12.61-52.106 is installed
OR kernel-ec2-devel-3.12.61-52.106 is installed
OR kernel-ec2-extra-3.12.61-52.106 is installed
Definition Synopsis |
SUSE Linux Enterprise Module for Web Scripting 12 is installed
AND Package Information
apache2-mod_php5-5.5.14-30 is installed
OR php5-5.5.14-30 is installed
OR php5-bcmath-5.5.14-30 is installed
OR php5-bz2-5.5.14-30 is installed
OR php5-calendar-5.5.14-30 is installed
OR php5-ctype-5.5.14-30 is installed
OR php5-curl-5.5.14-30 is installed
OR php5-dba-5.5.14-30 is installed
OR php5-dom-5.5.14-30 is installed
OR php5-enchant-5.5.14-30 is installed
OR php5-exif-5.5.14-30 is installed
OR php5-fastcgi-5.5.14-30 is installed
OR php5-fileinfo-5.5.14-30 is installed
OR php5-fpm-5.5.14-30 is installed
OR php5-ftp-5.5.14-30 is installed
OR php5-gd-5.5.14-30 is installed
OR php5-gettext-5.5.14-30 is installed
OR php5-gmp-5.5.14-30 is installed
OR php5-iconv-5.5.14-30 is installed
OR php5-intl-5.5.14-30 is installed
OR php5-json-5.5.14-30 is installed
OR php5-ldap-5.5.14-30 is installed
OR php5-mbstring-5.5.14-30 is installed
OR php5-mcrypt-5.5.14-30 is installed
OR php5-mysql-5.5.14-30 is installed
OR php5-odbc-5.5.14-30 is installed
OR php5-openssl-5.5.14-30 is installed
OR php5-pcntl-5.5.14-30 is installed
OR php5-pdo-5.5.14-30 is installed
OR php5-pear-5.5.14-30 is installed
OR php5-pgsql-5.5.14-30 is installed
OR php5-pspell-5.5.14-30 is installed
OR php5-shmop-5.5.14-30 is installed
OR php5-snmp-5.5.14-30 is installed
OR php5-soap-5.5.14-30 is installed
OR php5-sockets-5.5.14-30 is installed
OR php5-sqlite-5.5.14-30 is installed
OR php5-suhosin-5.5.14-30 is installed
OR php5-sysvmsg-5.5.14-30 is installed
OR php5-sysvsem-5.5.14-30 is installed
OR php5-sysvshm-5.5.14-30 is installed
OR php5-tokenizer-5.5.14-30 is installed
OR php5-wddx-5.5.14-30 is installed
OR php5-xmlreader-5.5.14-30 is installed
OR php5-xmlrpc-5.5.14-30 is installed
OR php5-xmlwriter-5.5.14-30 is installed
OR php5-xsl-5.5.14-30 is installed
OR php5-zip-5.5.14-30 is installed
OR php5-zlib-5.5.14-30 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 11 SP2 is installed
AND Package Information
apache2-mod_php5-5.2.14- is installed
OR php5-5.2.14- is installed
OR php5-bcmath-5.2.14- is installed
OR php5-bz2-5.2.14- is installed
OR php5-calendar-5.2.14- is installed
OR php5-ctype-5.2.14- is installed
OR php5-curl-5.2.14- is installed
OR php5-dba-5.2.14- is installed
OR php5-dbase-5.2.14- is installed
OR php5-dom-5.2.14- is installed
OR php5-exif-5.2.14- is installed
OR php5-fastcgi-5.2.14- is installed
OR php5-ftp-5.2.14- is installed
OR php5-gd-5.2.14- is installed
OR php5-gettext-5.2.14- is installed
OR php5-gmp-5.2.14- is installed
OR php5-hash-5.2.14- is installed
OR php5-iconv-5.2.14- is installed
OR php5-json-5.2.14- is installed
OR php5-ldap-5.2.14- is installed
OR php5-mbstring-5.2.14- is installed
OR php5-mcrypt-5.2.14- is installed
OR php5-mysql-5.2.14- is installed
OR php5-odbc-5.2.14- is installed
OR php5-openssl-5.2.14- is installed
OR php5-pcntl-5.2.14- is installed
OR php5-pdo-5.2.14- is installed
OR php5-pear-5.2.14- is installed
OR php5-pgsql-5.2.14- is installed
OR php5-pspell-5.2.14- is installed
OR php5-shmop-5.2.14- is installed
OR php5-snmp-5.2.14- is installed
OR php5-soap-5.2.14- is installed
OR php5-suhosin-5.2.14- is installed
OR php5-sysvmsg-5.2.14- is installed
OR php5-sysvsem-5.2.14- is installed
OR php5-sysvshm-5.2.14- is installed
OR php5-tokenizer-5.2.14- is installed
OR php5-wddx-5.2.14- is installed
OR php5-xmlreader-5.2.14- is installed
OR php5-xmlrpc-5.2.14- is installed
OR php5-xmlwriter-5.2.14- is installed
OR php5-xsl-5.2.14- is installed
OR php5-zip-5.2.14- is installed
OR php5-zlib-5.2.14- is installed
Definition Synopsis |
SUSE Linux Enterprise Server 11 SP2-LTSS is installed
AND Package Information
MozillaFirefox-24.6.0esr-0.3.1 is installed
OR MozillaFirefox-branding-SLED-24- is installed
OR MozillaFirefox-translations-24.6.0esr-0.3.1 is installed
OR libfreebl3-3.16.1-0.3.1 is installed
OR libfreebl3-32bit-3.16.1-0.3.1 is installed
OR mozilla-nspr-4.10.6-0.3.1 is installed
OR mozilla-nspr-32bit-4.10.6-0.3.1 is installed
OR mozilla-nspr-devel-4.10.6-0.3.1 is installed
OR mozilla-nss-3.16.1-0.3.1 is installed
OR mozilla-nss-32bit-3.16.1-0.3.1 is installed
OR mozilla-nss-devel-3.16.1-0.3.1 is installed
OR mozilla-nss-tools-3.16.1-0.3.1 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 11 SP4 is installed
AND Package Information
vte-0.22.5-0.2.1 is installed
OR vte-doc-0.22.5-0.2.1 is installed
OR vte-lang-0.22.5-0.2.1 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 12 is installed
AND libraptor2-0-2.0.10-3 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1 is installed
AND Package Information
automake-1.13.4-4 is installed
OR m4-1.4.16-15 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2 is installed
AND Package Information
apache-commons-daemon-1.0.15-4 is installed
OR apache-commons-daemon-javadoc-1.0.15-4 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
augeas-1.2.0-15 is installed
OR augeas-lenses-1.2.0-15 is installed
OR libaugeas0-1.2.0-15 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 12-LTSS is installed
AND Package Information
kgraft-patch-3_12_55-52_42-default-2-2.2 is installed
OR kgraft-patch-3_12_55-52_42-xen-2-2.2 is installed
OR kgraft-patch-SLE12_Update_12-2-2.2 is installed
Definition Synopsis |
SUSE Linux Enterprise Server 15-LTSS is installed
AND Package Information
freeradius-server-3.0.16-3.6 is installed
OR freeradius-server-devel-3.0.16-3.6 is installed
OR freeradius-server-krb5-3.0.16-3.6 is installed
OR freeradius-server-ldap-3.0.16-3.6 is installed
OR freeradius-server-libs-3.0.16-3.6 is installed
OR freeradius-server-mysql-3.0.16-3.6 is installed
OR freeradius-server-perl-3.0.16-3.6 is installed
OR freeradius-server-postgresql-3.0.16-3.6 is installed
OR freeradius-server-python-3.0.16-3.6 is installed
OR freeradius-server-sqlite-3.0.16-3.6 is installed
OR freeradius-server-utils-3.0.16-3.6 is installed
Definition Synopsis |
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 is installed
AND libXt6-1.1.4-3 is installed
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 15 is installed
AND permissions-20180125-3.21 is installed
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 11 SP3 is installed
AND Package Information
MozillaFirefox-devel-24.5.0esr-0.8.1 is installed
OR mozilla-nspr-devel-4.10.4-0.3.1 is installed
OR mozilla-nss-devel-3.16-0.8.1 is installed
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 12 is installed
AND Package Information
ImageMagick- is installed
OR ImageMagick-devel- is installed
OR libMagick++-6_Q16-3- is installed
OR libMagick++-devel- is installed
OR perl-PerlMagick- is installed
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 12 SP1 is installed
AND Package Information
fuse-devel-2.9.3-5 is installed
OR fuse-devel-static-2.9.3-5 is installed
OR libulockmgr1-2.9.3-5 is installed
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 12 SP2 is installed
AND Package Information
ghostscript-9.15-17.2 is installed
OR ghostscript-devel-9.15-17.2 is installed
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 12 is installed
AND Package Information
ImageMagick- is installed
OR libMagick++-6_Q16-3- is installed
OR libMagickCore-6_Q16-1-32bit- is installed
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 12 SP1 is installed
AND Package Information
kernel-default-3.12.51-60.20.2 is installed
OR kernel-default-extra-3.12.51-60.20.2 is installed
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 15 is installed
AND Package Information
kernel-default-4.12.14-25.6 is installed
OR kernel-default-extra-4.12.14-25.6 is installed
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
AND Package Information
kernel-default-4.12.14-197.4 is installed
OR kernel-default-extra-4.12.14-197.4 is installed
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
AND Package Information
MozillaThunderbird-68.9.0-3.85 is installed
OR MozillaThunderbird-translations-common-68.9.0-3.85 is installed
OR MozillaThunderbird-translations-other-68.9.0-3.85 is installed