Oval Definition:oval:org.opensuse.security:def:53097
Revision Date:2020-12-01Version:1
Title:Security update for python-azure-agent (Moderate)
Description:

This update for python-azure-agent fixes the following issues:

python-azure-agent was updated to version 2.2.45 (jsc#ECO-80)

+ Add support for Gen2 VM resource disks + Use alternate systemd detection + Fix /proc/net/route requirement that causes errors on FreeBSD + Add cloud-init auto-detect to prevent multiple provisioning mechanisms from relying on configuration for coordination + Disable cgroups when daemon is setup incorrectly + Remove upgrade extension loop for the same goal state + Add container id for extension telemetry events + Be more exact when detecting IMDS service health + Changing add_event to start sending missing fields

From 2.2.44 update:

+ Remove outdated extension ZIP packages + Improved error handling when starting extensions using systemd + Reduce provisioning time of some custom images + Improve the handling of extension download errors + New API for extension authors to handle errors during extension update + Fix handling of errors in calls to openssl + Improve logic to determine current distro + Reduce verbosity of several logging statements

From 2.2.42 update:

+ Poll for artifact blob, addresses goal state procesing issue

From 2.2.41 update:

+ Rewriting the mechanism to start the extension using systemd-run for systems using systemd for managing + Refactoring of resource monitoring framework using cgroup for both systemd and non-systemd approaches [#1530, #1534] + Telemetry pipeline for resource monitoring data

From 2.2.40 update:

+ Fixed tracking of memory/cpu usage + Do not prevent extensions from running if setting up cgroups fails + Enable systemd-aware deprovisioning on all versions >= 18.04 + Add systemd support for Debian Jessie, Stretch, and Buster + Support for Linux Openwrt

From 2.2.38 update:

Security issue fixed: + CVE-2019-0804: An issue with swapfile handling in the agent creates a data leak situation that exposes system memory data. (bsc#1127838) + Add fixes for handling swap file and other nit fixes

From 2.2.37 update: + Improves re-try logic to handle errors while downloading extensions

Family:unixClass:patch
Status:Reference(s):1004221
1020108
1051510
1058115
1065600
1065729
1071995
1082555
1083647
1085030
1089895
1090036
1103990
1103991
1103992
1104745
1109837
1111666
1112178
1112374
1113956
1114279
1124278
1127354
1127355
1127371
1127838
1133021
1137325
1142685
1144333
1145929
1148868
1150660
1151794
1151927
1152489
1152624
1154824
1157169
1158265
1158983
1159037
1159058
1159199
1160388
1160947
1161016
1162002
1162063
1163309
1163403
1163897
1164284
1164780
1164871
1165183
1165478
1165741
1166780
1166860
1166861
1166862
1166864
1166866
1166867
1166868
1166870
1166940
1166969
1166978
1166985
1167104
1167288
1167574
1167851
1167867
1168081
1168202
1168332
1168486
1168670
1168760
1168762
1168763
1168764
1168765
1168789
1168881
1168884
1168952
1168959
1169020
1169057
1169194
1169390
1169514
1169525
1169625
1169762
1169771
1169795
1170011
1170056
1170125
1170145
1170284
1170345
1170442
1170457
1170522
1170592
1170617
1170618
1170620
1170621
1170770
1170778
1170791
1170901
1171078
1171098
1171118
1171124
1171189
1171191
1171195
1171202
1171205
1171214
1171217
1171218
1171219
1171220
1171244
1171293
1171417
1171424
1171527
1171529
1171530
1171558
1171599
1171600
1171601
1171602
1171604
1171605
1171606
1171607
1171608
1171609
1171610
1171611
1171612
1171613
1171614
1171615
1171616
1171617
1171618
1171619
1171620
1171621
1171622
1171623
1171624
1171625
1171626
1171662
1171679
1171691
1171692
1171694
1171695
1171732
1171736
1171739
1171743
1171753
1171759
1171817
1171835
1171841
1171868
1171904
1171948
1171949
1171951
1171952
1171979
1171982
1171983
1171988
1172017
1172096
1172097
1172098
1172099
1172101
1172102
1172103
1172104
1172127
1172130
1172185
1172188
1172199
1172201
1172202
1172221
1172247
1172249
1172251
1172257
1172317
1172342
1172343
1172344
1172366
1172378
1172391
1172397
1172453
1172458
1172484
1172537
1172538
1172687
1172719
1172759
1172775
1172781
1172782
1172783
1172871
1172872
1172999
1173060
1173074
1173146
1173265
1173280
1173284
1173428
1173514
1173567
1173573
1173746
1173818
1173820
1173825
1173826
1173833
1173838
1173839
1173845
1173857
1174113
1174115
1174122
1174123
1174186
1174187
1174296
1174343
1174356
1174409
1174438
1174462
902676
902677
903655
905735
905736
949520
963448
980670
998309
CVE-2010-4000
CVE-2011-1000
CVE-2012-0804
CVE-2013-1431
CVE-2013-1989
CVE-2013-2002
CVE-2013-2005
CVE-2013-2066
CVE-2014-8104
CVE-2014-8484
CVE-2014-8484
CVE-2014-8485
CVE-2014-8485
CVE-2014-8501
CVE-2014-8501
CVE-2014-8502
CVE-2014-8502
CVE-2014-8503
CVE-2014-8503
CVE-2014-8504
CVE-2014-8504
CVE-2014-8737
CVE-2014-8737
CVE-2014-8738
CVE-2014-8738
CVE-2015-1782
CVE-2015-3223
CVE-2015-5330
CVE-2016-0787
CVE-2016-1602
CVE-2016-2037
CVE-2016-6662
CVE-2016-8605
CVE-2017-8288
CVE-2018-1000199
CVE-2019-0804
CVE-2019-19462
CVE-2019-20806
CVE-2019-20810
CVE-2019-20812
CVE-2019-20908
CVE-2019-9455
CVE-2020-0305
CVE-2020-0543
CVE-2020-10135
CVE-2020-10690
CVE-2020-10711
CVE-2020-10720
CVE-2020-10732
CVE-2020-10751
CVE-2020-10757
CVE-2020-10766
CVE-2020-10767
CVE-2020-10768
CVE-2020-10769
CVE-2020-10773
CVE-2020-10781
CVE-2020-11669
CVE-2020-12114
CVE-2020-12464
CVE-2020-12652
CVE-2020-12653
CVE-2020-12654
CVE-2020-12655
CVE-2020-12656
CVE-2020-12657
CVE-2020-12659
CVE-2020-12769
CVE-2020-12771
CVE-2020-12888
CVE-2020-13143
CVE-2020-13974
CVE-2020-14416
CVE-2020-15393
CVE-2020-15780
SUSE-SU-2016:1507-1
SUSE-SU-2016:2404-1
SUSE-SU-2017:0366-1
SUSE-SU-2017:0398-1
SUSE-SU-2020:0440-1
SUSE-SU-2020:2487-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Module for Public Cloud 15 SP1
SUSE Linux Enterprise Module for Realtime packages 15 SP1
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND chrony-3.2-lp150.5 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libwavpack1-5.1.0-lp151.5.3 is installed
  • OR libwavpack1-32bit-5.1.0-lp151.5.3 is installed
  • OR wavpack-5.1.0-lp151.5.3 is installed
  • OR wavpack-devel-5.1.0-lp151.5.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • libgcrypt11-1.5.0-0.17 is installed
  • OR libgcrypt11-32bit-1.5.0-0.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • flash-player-11.2.202.540-0.23 is installed
  • OR flash-player-gnome-11.2.202.540-0.23 is installed
  • OR flash-player-kde4-11.2.202.540-0.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND binutils-2.24-7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • libmysqlclient18-10.0.27-12 is installed
  • OR libmysqlclient18-32bit-10.0.27-12 is installed
  • OR libmysqlclient_r18-10.0.27-12 is installed
  • OR libmysqlclient_r18-32bit-10.0.27-12 is installed
  • OR mariadb-10.0.27-12 is installed
  • OR mariadb-client-10.0.27-12 is installed
  • OR mariadb-errormessages-10.0.27-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND cvs-1.12.12-181 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND binutils-2.26.1-9.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Public Cloud 15 SP1 is installed
  • AND python-azure-agent-2.2.45-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Realtime packages 15 SP1 is installed
  • AND Package Information
  • cluster-md-kmp-rt-4.12.14-14.28 is installed
  • OR dlm-kmp-rt-4.12.14-14.28 is installed
  • OR gfs2-kmp-rt-4.12.14-14.28 is installed
  • OR kernel-devel-rt-4.12.14-14.28 is installed
  • OR kernel-rt-4.12.14-14.28 is installed
  • OR kernel-rt-base-4.12.14-14.28 is installed
  • OR kernel-rt-devel-4.12.14-14.28 is installed
  • OR kernel-rt_debug-4.12.14-14.28 is installed
  • OR kernel-rt_debug-devel-4.12.14-14.28 is installed
  • OR kernel-source-rt-4.12.14-14.28 is installed
  • OR kernel-syms-rt-4.12.14-14.28 is installed
  • OR ocfs2-kmp-rt-4.12.14-14.28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • libgoa-1_0-0-3.10.5-1 is installed
  • OR libgoa-backend-1_0-1-3.10.5-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_74-60_64_60-default-2-4 is installed
  • OR kgraft-patch-3_12_74-60_64_60-xen-2-4 is installed
  • OR kgraft-patch-SLE12-SP1_Update_21-2-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • gv-3.7.4-1 is installed
  • OR wdiff-1.2.1-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • glibc-2.22-62.13 is installed
  • OR glibc-32bit-2.22-62.13 is installed
  • OR glibc-devel-2.22-62.13 is installed
  • OR glibc-devel-32bit-2.22-62.13 is installed
  • OR glibc-html-2.22-62.13 is installed
  • OR glibc-i18ndata-2.22-62.13 is installed
  • OR glibc-info-2.22-62.13 is installed
  • OR glibc-locale-2.22-62.13 is installed
  • OR glibc-locale-32bit-2.22-62.13 is installed
  • OR glibc-profile-2.22-62.13 is installed
  • OR glibc-profile-32bit-2.22-62.13 is installed
  • OR nscd-2.22-62.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • glibc-2.22-62.13 is installed
  • OR glibc-32bit-2.22-62.13 is installed
  • OR glibc-devel-2.22-62.13 is installed
  • OR glibc-devel-32bit-2.22-62.13 is installed
  • OR glibc-html-2.22-62.13 is installed
  • OR glibc-i18ndata-2.22-62.13 is installed
  • OR glibc-info-2.22-62.13 is installed
  • OR glibc-locale-2.22-62.13 is installed
  • OR glibc-locale-32bit-2.22-62.13 is installed
  • OR glibc-profile-2.22-62.13 is installed
  • OR glibc-profile-32bit-2.22-62.13 is installed
  • OR nscd-2.22-62.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_59-92_20-default-12-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_8-12-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libkde4-4.12.0-10 is installed
  • OR libkde4-32bit-4.12.0-10 is installed
  • OR libkdecore4-4.12.0-10 is installed
  • OR libkdecore4-32bit-4.12.0-10 is installed
  • OR libksuseinstall1-4.12.0-10 is installed
  • OR libksuseinstall1-32bit-4.12.0-10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • MozillaFirefox-60.9.0-109.86 is installed
  • OR MozillaFirefox-translations-common-60.9.0-109.86 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND sudo-1.8.20p2-3.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • dovecot22-2.2.31-19.17 is installed
  • OR dovecot22-backend-mysql-2.2.31-19.17 is installed
  • OR dovecot22-backend-pgsql-2.2.31-19.17 is installed
  • OR dovecot22-backend-sqlite-2.2.31-19.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.24.0-2.38 is installed
  • OR libwebkit2gtk-4_0-37-2.24.0-2.38 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.24.0-2.38 is installed
  • OR typelib-1_0-WebKit2-4_0-2.24.0-2.38 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.24.0-2.38 is installed
  • OR webkit2gtk3-2.24.0-2.38 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND davfs2-1.5.2-2 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND Package Information
  • libmysqlclient-devel-10.0.31-29.3 is installed
  • OR libmysqlclient18-10.0.31-29.3 is installed
  • OR libmysqlclient18-32bit-10.0.31-29.3 is installed
  • OR libmysqlclient_r18-10.0.31-29.3 is installed
  • OR libmysqld-devel-10.0.31-29.3 is installed
  • OR libmysqld18-10.0.31-29.3 is installed
  • OR mariadb-10.0.31-29.3 is installed
  • OR mariadb-client-10.0.31-29.3 is installed
  • OR mariadb-errormessages-10.0.31-29.3 is installed
  • OR mariadb-tools-10.0.31-29.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND python-tablib-0.9.11-3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND python-Twisted-15.2.1-9.5 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND python-ecdsa-0.13.3-5.10 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.222-27.35 is installed
  • BACK