Oval Definition:oval:org.opensuse.security:def:51979
Revision Date:2022-12-29Version:1
Title:Security update for conmon (Moderate)
Description:

This update for conmon fixes the following issues:

conmon was updated to version 2.1.5:

don't leak syslog_identifier * logging: do not read more that the buf size * logging: fix error handling * Makefile: Fix install for FreeBSD * signal: Track changes to get_signal_descriptor in the FreeBSD version * Packit: initial enablement

Update to version 2.1.4:

Fix a bug where conmon crashed when it got a SIGCHLD

update to 2.1.3:

Stop using g_unix_signal_add() to avoid threads * Rename CLI optionlog-size-global-max to log-global-size-max

Update to version 2.1.2:

* add log-global-size-max option to limit the total output conmon processes (CVE-2022-1708 bsc#1200285) * journald: print tag and name if both are specified * drop some logs to debug level

Update to version 2.1.0

logging: buffer partial messages to journald * exit: close all fds >= 3 * fix: cgroup: Free memory_cgroup_file_path if open fails.

Update to version 2.0.32

Fix: Avoid mainfd_std{in,out} sharing the same file descriptor. * exit_command: Fix: unset subreaper attribute before running exit command

Update to version 2.0.31 * logging: new mode -l passthrough * ctr_logs: use container name or ID as SYSLOG_IDENTIFIER for journald * conmon: Fix: free userdata files before exec cleanup
Family:unixClass:patch
Status:Reference(s):1073313
1093447
1093536
1094462
1107874
1109845
1111388
1111966
1114845
1131055
1136085
1143194
1143273
1152692
1155327
1159670
1166881
1168345
1171999
1173376
1173377
1173378
1173380
1175987
1176024
1176294
1176397
1177867
1178319
1178361
1178362
1178485
1183909
1184519
1188941
1191473
1192267
1200285
CVE-2008-5984
CVE-2009-0163
CVE-2009-2820
CVE-2009-3553
CVE-2009-3736
CVE-2010-0393
CVE-2010-0540
CVE-2010-0542
CVE-2010-1748
CVE-2010-2941
CVE-2011-1006
CVE-2011-1022
CVE-2011-2199
CVE-2012-5519
CVE-2012-6094
CVE-2013-2002
CVE-2013-2003
CVE-2013-2005
CVE-2014-2856
CVE-2014-3537
CVE-2014-5029
CVE-2014-5030
CVE-2014-5031
CVE-2014-9679
CVE-2015-1158
CVE-2015-1159
CVE-2016-5180
CVE-2017-17740
CVE-2018-10196
CVE-2018-10811
CVE-2018-16151
CVE-2018-16152
CVE-2018-17540
CVE-2018-5388
CVE-2019-0199
CVE-2019-0221
CVE-2019-11048
CVE-2019-13057
CVE-2019-13565
CVE-2020-11501
CVE-2020-15563
CVE-2020-15565
CVE-2020-15566
CVE-2020-15567
CVE-2020-16846
CVE-2020-17490
CVE-2020-25592
CVE-2021-20294
CVE-2022-1708
SUSE-SU-2019:1693-1
SUSE-SU-2019:2395-1
SUSE-SU-2019:3056-1
SUSE-SU-2020:0948-1
SUSE-SU-2020:1661-1
SUSE-SU-2020:2346-1
SUSE-SU-2020:3244-1
SUSE-SU-2021:3637-1
SUSE-SU-2022:4635-1
Platform(s):openSUSE Leap 15.0
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Module for Server Applications 15 SP1
SUSE Linux Enterprise Module for Web Scripting 15
SUSE Linux Enterprise Module for Web Scripting 15 SP1
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 15-LTSS
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • gegl-0_3-0.3.34-lp150.1 is installed
  • OR gegl-0_3-lang-0.3.34-lp150.1 is installed
  • OR libgegl-0_3-0-0.3.34-lp150.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • xorg-x11-libXt-7.4-1.19 is installed
  • OR xorg-x11-libXt-32bit-7.4-1.19 is installed
  • OR xorg-x11-libXt-devel-7.4-1.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • MozillaFirefox-17.0.9esr-0.7 is installed
  • OR MozillaFirefox-translations-17.0.9esr-0.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • libXt6-1.1.4-3 is installed
  • OR libXt6-32bit-1.1.4-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • cups-1.7.5-9 is installed
  • OR cups-client-1.7.5-9 is installed
  • OR cups-libs-1.7.5-9 is installed
  • OR cups-libs-32bit-1.7.5-9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • dia-0.97.3-15 is installed
  • OR dia-lang-0.97.3-15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • libXcursor1-1.1.14-3 is installed
  • OR libXcursor1-32bit-1.1.14-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • bash-4.3-83.15 is installed
  • OR bash-doc-4.3-83.15 is installed
  • OR bash-lang-4.3-83.15 is installed
  • OR libreadline6-6.3-83.15 is installed
  • OR libreadline6-32bit-6.3-83.15 is installed
  • OR readline-doc-6.3-83.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND conmon-2.1.5-150400.3.3.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • libldap-data-2.4.46-9.19 is installed
  • OR openldap2-2.4.46-9.19 is installed
  • OR openldap2-back-sock-2.4.46-9.19 is installed
  • OR openldap2-back-sql-2.4.46-9.19 is installed
  • OR openldap2-contrib-2.4.46-9.19 is installed
  • OR openldap2-doc-2.4.46-9.19 is installed
  • OR openldap2-ppolicy-check-password-1.2-9.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND Package Information
  • graphviz-addons-2.40.1-6.6 is installed
  • OR graphviz-tcl-2.40.1-6.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Web Scripting 15 is installed
  • AND Package Information
  • tomcat-9.0.20-3.24 is installed
  • OR tomcat-admin-webapps-9.0.20-3.24 is installed
  • OR tomcat-el-3_0-api-9.0.20-3.24 is installed
  • OR tomcat-jsp-2_3-api-9.0.20-3.24 is installed
  • OR tomcat-lib-9.0.20-3.24 is installed
  • OR tomcat-servlet-4_0-api-9.0.20-3.24 is installed
  • OR tomcat-webapps-9.0.20-3.24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Web Scripting 15 SP1 is installed
  • AND Package Information
  • apache2-mod_php7-7.2.5-4.58 is installed
  • OR php7-7.2.5-4.58 is installed
  • OR php7-bcmath-7.2.5-4.58 is installed
  • OR php7-bz2-7.2.5-4.58 is installed
  • OR php7-calendar-7.2.5-4.58 is installed
  • OR php7-ctype-7.2.5-4.58 is installed
  • OR php7-curl-7.2.5-4.58 is installed
  • OR php7-dba-7.2.5-4.58 is installed
  • OR php7-devel-7.2.5-4.58 is installed
  • OR php7-dom-7.2.5-4.58 is installed
  • OR php7-enchant-7.2.5-4.58 is installed
  • OR php7-exif-7.2.5-4.58 is installed
  • OR php7-fastcgi-7.2.5-4.58 is installed
  • OR php7-fileinfo-7.2.5-4.58 is installed
  • OR php7-fpm-7.2.5-4.58 is installed
  • OR php7-ftp-7.2.5-4.58 is installed
  • OR php7-gd-7.2.5-4.58 is installed
  • OR php7-gettext-7.2.5-4.58 is installed
  • OR php7-gmp-7.2.5-4.58 is installed
  • OR php7-iconv-7.2.5-4.58 is installed
  • OR php7-intl-7.2.5-4.58 is installed
  • OR php7-json-7.2.5-4.58 is installed
  • OR php7-ldap-7.2.5-4.58 is installed
  • OR php7-mbstring-7.2.5-4.58 is installed
  • OR php7-mysql-7.2.5-4.58 is installed
  • OR php7-odbc-7.2.5-4.58 is installed
  • OR php7-opcache-7.2.5-4.58 is installed
  • OR php7-openssl-7.2.5-4.58 is installed
  • OR php7-pcntl-7.2.5-4.58 is installed
  • OR php7-pdo-7.2.5-4.58 is installed
  • OR php7-pear-7.2.5-4.58 is installed
  • OR php7-pear-Archive_Tar-7.2.5-4.58 is installed
  • OR php7-pgsql-7.2.5-4.58 is installed
  • OR php7-phar-7.2.5-4.58 is installed
  • OR php7-posix-7.2.5-4.58 is installed
  • OR php7-readline-7.2.5-4.58 is installed
  • OR php7-shmop-7.2.5-4.58 is installed
  • OR php7-snmp-7.2.5-4.58 is installed
  • OR php7-soap-7.2.5-4.58 is installed
  • OR php7-sockets-7.2.5-4.58 is installed
  • OR php7-sodium-7.2.5-4.58 is installed
  • OR php7-sqlite-7.2.5-4.58 is installed
  • OR php7-sysvmsg-7.2.5-4.58 is installed
  • OR php7-sysvsem-7.2.5-4.58 is installed
  • OR php7-sysvshm-7.2.5-4.58 is installed
  • OR php7-tidy-7.2.5-4.58 is installed
  • OR php7-tokenizer-7.2.5-4.58 is installed
  • OR php7-wddx-7.2.5-4.58 is installed
  • OR php7-xmlreader-7.2.5-4.58 is installed
  • OR php7-xmlrpc-7.2.5-4.58 is installed
  • OR php7-xmlwriter-7.2.5-4.58 is installed
  • OR php7-xsl-7.2.5-4.58 is installed
  • OR php7-zip-7.2.5-4.58 is installed
  • OR php7-zlib-7.2.5-4.58 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • libupsclient1-2.7.1-4 is installed
  • OR nut-2.7.1-4 is installed
  • OR nut-drivers-net-2.7.1-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • libsqlite3-0-3.8.10.2-9.15 is installed
  • OR libsqlite3-0-32bit-3.8.10.2-9.15 is installed
  • OR sqlite3-3.8.10.2-9.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • eog-3.20.4-7 is installed
  • OR eog-lang-3.20.4-7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • openslp-2.0.0-18.15 is installed
  • OR openslp-32bit-2.0.0-18.15 is installed
  • OR openslp-server-2.0.0-18.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libopenssl-devel-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-32bit-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-hmac-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.39 is installed
  • OR openssl-1.0.2j-60.39 is installed
  • OR openssl-doc-1.0.2j-60.39 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_114-92_64-default-4-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_18-4-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND clamav-0.99.2-32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libpython3_4m1_0-3.4.10-25.39 is installed
  • OR python3-3.4.10-25.39 is installed
  • OR python3-base-3.4.10-25.39 is installed
  • OR python3-curses-3.4.10-25.39 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND binutils-2.32-9.33 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • glibc-2.22-62.22 is installed
  • OR glibc-32bit-2.22-62.22 is installed
  • OR glibc-devel-2.22-62.22 is installed
  • OR glibc-devel-32bit-2.22-62.22 is installed
  • OR glibc-html-2.22-62.22 is installed
  • OR glibc-i18ndata-2.22-62.22 is installed
  • OR glibc-info-2.22-62.22 is installed
  • OR glibc-locale-2.22-62.22 is installed
  • OR glibc-locale-32bit-2.22-62.22 is installed
  • OR glibc-profile-2.22-62.22 is installed
  • OR glibc-profile-32bit-2.22-62.22 is installed
  • OR nscd-2.22-62.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • gnutls-3.3.27-3.3 is installed
  • OR libgnutls-openssl27-3.3.27-3.3 is installed
  • OR libgnutls28-3.3.27-3.3 is installed
  • OR libgnutls28-32bit-3.3.27-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • bzip2-1.0.6-29 is installed
  • OR bzip2-doc-1.0.6-29 is installed
  • OR libbz2-1-1.0.6-29 is installed
  • OR libbz2-1-32bit-1.0.6-29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 15-LTSS is installed
  • AND Package Information
  • xen-4.10.4_12-3.35 is installed
  • OR xen-devel-4.10.4_12-3.35 is installed
  • OR xen-libs-4.10.4_12-3.35 is installed
  • OR xen-tools-4.10.4_12-3.35 is installed
  • OR xen-tools-domU-4.10.4_12-3.35 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND Package Information
  • binutils-2.37-9.44.1 is installed
  • OR binutils-devel-2.37-9.44.1 is installed
  • OR libctf-nobfd0-2.37-9.44.1 is installed
  • OR libctf0-2.37-9.44.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • AND Package Information
  • python2-salt-3000-5.91 is installed
  • OR python3-salt-3000-5.91 is installed
  • OR salt-3000-5.91 is installed
  • OR salt-api-3000-5.91 is installed
  • OR salt-bash-completion-3000-5.91 is installed
  • OR salt-cloud-3000-5.91 is installed
  • OR salt-doc-3000-5.91 is installed
  • OR salt-fish-completion-3000-5.91 is installed
  • OR salt-master-3000-5.91 is installed
  • OR salt-minion-3000-5.91 is installed
  • OR salt-proxy-3000-5.91 is installed
  • OR salt-ssh-3000-5.91 is installed
  • OR salt-standalone-formulas-configuration-3000-5.91 is installed
  • OR salt-syndic-3000-5.91 is installed
  • OR salt-zsh-completion-3000-5.91 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND ntp-4.2.8p4-1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • python-oslo.cache-1.14.1-3.3 is installed
  • OR python-oslo.concurrency-3.14.1-3.3 is installed
  • OR python-oslo.db-4.13.6-3.3 is installed
  • OR python-oslo.log-3.16.1-3.3 is installed
  • OR python-oslo.messaging-5.10.2-3.6 is installed
  • OR python-oslo.middleware-3.19.1-4.3 is installed
  • OR python-oslo.serialization-2.13.2-3.3 is installed
  • OR python-oslo.service-1.16.1-3.3 is installed
  • OR python-oslo.utils-3.16.1-3.3 is installed
  • OR python-oslo.versionedobjects-1.17.1-3.3 is installed
  • OR python-oslo.vmware-2.14.1-3.3 is installed
  • OR python-oslotest-2.10.1-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libpython3_4m1_0-3.4.6-25.29 is installed
  • OR python3-3.4.6-25.29 is installed
  • OR python3-base-3.4.6-25.29 is installed
  • OR python3-curses-3.4.6-25.29 is installed
  • BACK