Revision Date: | 2020-12-01 | Version: | 1 |
Title: | Security update for rmt-server (Important) |
Description: |
This update for rmt-server fixes the following issues:
Update to version 2.6.5: - Solved potential bug of SCC repository URLs changing over time. RMT now self heals by removing the previous invalid repository and creating the correct one. - Add web server settings to /etc/rmt.conf: Now it's possible to configure the minimum and maximum threads count as well the number of web server workers to be booted through /etc/rmt.conf. - Instead of using an MD5 of URLs for custom repository friendly_ids, RMT now builds an ID from the name. - Fix RMT file caching based on timestamps: Previously, RMT sent GET requests with the header 'If-Modified-Since' to a repository server and if the response had a 304 (Not Modified), it would copy a file from the local cache instead of downloading. However, if the local file timestamp accidentally changed to a date newer than the one on the repository server, RMT would have an outdated file, which caused some errors. Now, RMT makes HEAD requests to the repositories servers and inspect the 'Last-Modified' header to decide whether to download a file or copy it from cache, by comparing the equalness of timestamps. - Fixed an issue where relative paths supplied to `rmt-cli import repos` caused the command to fail. - Friendlier IDs for custom repositories: In an effort to simplify the handling of SCC and custom repositories, RMT now has friendly IDs. For SCC repositories, it's the same SCC ID as before. For custom repositories, it can either be user provided or RMT generated (MD5 of the provided URL). Benefits: * `rmt-cli mirror repositories` now works for custom repositories. * Custom repository IDs can be the same across RMT instances. * No more confusing 'SCC ID' vs 'ID' in `rmt-cli` output. Deprecation Warnings: * RMT now uses a different ID for custom repositories than before. RMT still supports that old ID, but it's recommended to start using the new ID to ensure future compatibility. - Updated rails and puma dependencies for security fixes.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1000195 1002496 1005028 1007188 1008965 1012504 1012632 1012651 1014298 1014300 1015169 1015941 1016340 1019332 1020077 1020985 1022871 1023004 1023041 1024834 1069496 1069702 1070805 1163102 1163103 1163104 1165548 1168554 1172177 1172182 1172184 1172186 1173351 902676 902677 903655 905735 905736 913058 966435 966436 CVE-2007-3126 CVE-2007-4772 CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-2896 CVE-2012-2669 CVE-2012-3236 CVE-2012-5532 CVE-2012-5576 CVE-2013-1991 CVE-2013-2000 CVE-2014-3675 CVE-2014-3676 CVE-2014-3677 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2014-8484 CVE-2014-8485 CVE-2014-8501 CVE-2014-8502 CVE-2014-8503 CVE-2014-8504 CVE-2014-8737 CVE-2014-8738 CVE-2014-9636 CVE-2014-9913 CVE-2015-7696 CVE-2015-7697 CVE-2015-7747 CVE-2016-0766 CVE-2016-0773 CVE-2016-2399 CVE-2016-4994 CVE-2016-6321 CVE-2016-9844 CVE-2016-9921 CVE-2016-9922 CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 CVE-2017-1000405 CVE-2017-16939 CVE-2017-2615 CVE-2017-2616 CVE-2017-2620 CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833 CVE-2017-6834 CVE-2017-6835 CVE-2017-6836 CVE-2017-6837 CVE-2017-6838 CVE-2017-6839 CVE-2018-1000035 CVE-2019-15604 CVE-2019-15605 CVE-2019-15606 CVE-2019-16770 CVE-2019-5418 CVE-2019-5419 CVE-2019-5420 CVE-2020-11076 CVE-2020-11077 CVE-2020-15169 CVE-2020-5247 CVE-2020-5249 CVE-2020-5267 CVE-2020-8164 CVE-2020-8165 CVE-2020-8166 CVE-2020-8167 CVE-2020-8184 CVE-2020-8185 SUSE-SU-2016:0539-1 SUSE-SU-2016:2896-1 SUSE-SU-2016:3250-1 SUSE-SU-2017:0554-1 SUSE-SU-2017:0571-1 SUSE-SU-2017:3226-1 SUSE-SU-2020:0455-1 SUSE-SU-2020:3036-1
|
Platform(s): | openSUSE Leap 15.0 openSUSE Leap 15.1 SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Desktop 12 SP1 SUSE Linux Enterprise Desktop 12 SP2 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Desktop 12 SP4 SUSE Linux Enterprise Module for Server Applications 15 SP2 SUSE Linux Enterprise Module for Web Scripting 15 SP1 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP1-LTSS SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP2-BCL SUSE Linux Enterprise Server 12 SP2-ESPOS SUSE Linux Enterprise Server 12 SP2-LTSS SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP3-BCL SUSE Linux Enterprise Server 12 SP3-ESPOS SUSE Linux Enterprise Server 12 SP3-LTSS SUSE Linux Enterprise Server 12 SP3-TERADATA SUSE Linux Enterprise Server 12 SP4 SUSE OpenStack Cloud 6 SUSE OpenStack Cloud 7 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.0 is installed AND Package Information
elfutils-0.168-lp150.2 is installed
OR elfutils-lang-0.168-lp150.2 is installed
OR libasm1-0.168-lp150.2 is installed
OR libdw1-0.168-lp150.2 is installed
OR libdw1-32bit-0.168-lp150.2 is installed
OR libebl-plugins-0.168-lp150.2 is installed
OR libebl-plugins-32bit-0.168-lp150.2 is installed
OR libelf1-0.168-lp150.2 is installed
OR libelf1-32bit-0.168-lp150.2 is installed
|
Definition Synopsis |
openSUSE Leap 15.1 is installed
AND Package Information
neovim-0.3.7-lp151.2.7 is installed
OR neovim-lang-0.3.7-lp151.2.7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP2 is installed
AND Package Information
gtk2-2.18.9-0.23 is installed
OR gtk2-32bit-2.18.9-0.23 is installed
OR gtk2-devel-2.18.9-0.23 is installed
OR gtk2-lang-2.18.9-0.23 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP3 is installed
AND Package Information
MozillaFirefox-24.5.0esr-0.8 is installed
OR MozillaFirefox-branding-SLED-24-0.7 is installed
OR MozillaFirefox-translations-24.5.0esr-0.8 is installed
OR libfreebl3-3.16-0.8 is installed
OR libfreebl3-32bit-3.16-0.8 is installed
OR libsoftokn3-3.16-0.8 is installed
OR libsoftokn3-32bit-3.16-0.8 is installed
OR mozilla-nspr-4.10.4-0.3 is installed
OR mozilla-nspr-32bit-4.10.4-0.3 is installed
OR mozilla-nss-3.16-0.8 is installed
OR mozilla-nss-32bit-3.16-0.8 is installed
OR mozilla-nss-tools-3.16-0.8 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP4 is installed
AND Package Information
libopenssl0_9_8-0.9.8j-0.80 is installed
OR libopenssl0_9_8-32bit-0.9.8j-0.80 is installed
OR openssl-0.9.8j-0.80 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 is installed
AND binutils-2.24-7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP1 is installed
AND Package Information
tar-1.27.1-11 is installed
OR tar-lang-1.27.1-11 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP2 is installed
AND Package Information
libgme-0.6.0-5 is installed
OR libgme0-0.6.0-5 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed
AND Package Information
audiofile-0.3.6-10 is installed
OR libaudiofile1-0.3.6-10 is installed
OR libaudiofile1-32bit-0.3.6-10 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP4 is installed
AND Package Information
gimp-2.8.18-9.3 is installed
OR gimp-lang-2.8.18-9.3 is installed
OR gimp-plugins-python-2.8.18-9.3 is installed
OR libgimp-2_0-0-2.8.18-9.3 is installed
OR libgimpui-2_0-0-2.8.18-9.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
AND Package Information
rmt-server-2.6.5-3.3 is installed
OR rmt-server-config-2.6.5-3.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Web Scripting 15 SP1 is installed
AND Package Information
nodejs10-10.19.0-1.18 is installed
OR nodejs10-devel-10.19.0-1.18 is installed
OR nodejs10-docs-10.19.0-1.18 is installed
OR npm10-10.19.0-1.18 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1 is installed
AND Package Information
cups-1.7.5-9 is installed
OR cups-client-1.7.5-9 is installed
OR cups-libs-1.7.5-9 is installed
OR cups-libs-32bit-1.7.5-9 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1-LTSS is installed
AND Package Information
kgraft-patch-3_12_67-60_64_24-default-6-3 is installed
OR kgraft-patch-3_12_67-60_64_24-xen-6-3 is installed
OR kgraft-patch-SLE12-SP1_Update_11-6-3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2 is installed
AND ppp-2.4.7-1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-BCL is installed
AND Package Information
libsystemd0-228-150.82 is installed
OR libsystemd0-32bit-228-150.82 is installed
OR libudev1-228-150.82 is installed
OR libudev1-32bit-228-150.82 is installed
OR systemd-228-150.82 is installed
OR systemd-32bit-228-150.82 is installed
OR systemd-bash-completion-228-150.82 is installed
OR systemd-sysvinit-228-150.82 is installed
OR udev-228-150.82 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
AND Package Information
kernel-default-4.4.121-92.95 is installed
OR kernel-default-base-4.4.121-92.95 is installed
OR kernel-default-devel-4.4.121-92.95 is installed
OR kernel-devel-4.4.121-92.95 is installed
OR kernel-macros-4.4.121-92.95 is installed
OR kernel-source-4.4.121-92.95 is installed
OR kernel-syms-4.4.121-92.95 is installed
OR lttng-modules-2.7.1-9.6 is installed
OR lttng-modules-kmp-default-2.7.1_k4.4.121_92.95-9.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-LTSS is installed
AND Package Information
libssh2-1-1.4.3-20.6 is installed
OR libssh2-1-32bit-1.4.3-20.6 is installed
OR libssh2_org-1.4.3-20.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
java-1_7_1-ibm-1.7.1_sr4.5-37 is installed
OR java-1_7_1-ibm-alsa-1.7.1_sr4.5-37 is installed
OR java-1_7_1-ibm-jdbc-1.7.1_sr4.5-37 is installed
OR java-1_7_1-ibm-plugin-1.7.1_sr4.5-37 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-BCL is installed
AND Package Information
java-1_8_0-ibm-1.8.0_sr5.40-30.54 is installed
OR java-1_8_0-ibm-alsa-1.8.0_sr5.40-30.54 is installed
OR java-1_8_0-ibm-plugin-1.8.0_sr5.40-30.54 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
AND Package Information
libsolv-0.6.36-2.27.19 is installed
OR libsolv-tools-0.6.36-2.27.19 is installed
OR libzypp-16.20.2-27.60 is installed
OR perl-solv-0.6.36-2.27.19 is installed
OR python-solv-0.6.36-2.27.19 is installed
OR zypper-1.13.54-18.40 is installed
OR zypper-log-1.13.54-18.40 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-LTSS is installed
AND Package Information
perl-5.18.2-12.20 is installed
OR perl-32bit-5.18.2-12.20 is installed
OR perl-base-5.18.2-12.20 is installed
OR perl-doc-5.18.2-12.20 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
AND Package Information
cups-1.7.5-20.17 is installed
OR cups-client-1.7.5-20.17 is installed
OR cups-libs-1.7.5-20.17 is installed
OR cups-libs-32bit-1.7.5-20.17 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP4 is installed
AND Package Information
cvs-1.12.12-182.3 is installed
OR cvs-doc-1.12.12-182.3 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 6 is installed
AND Package Information
xen-4.5.5_24-22.43 is installed
OR xen-doc-html-4.5.5_24-22.43 is installed
OR xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43 is installed
OR xen-libs-4.5.5_24-22.43 is installed
OR xen-libs-32bit-4.5.5_24-22.43 is installed
OR xen-tools-4.5.5_24-22.43 is installed
OR xen-tools-domU-4.5.5_24-22.43 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 7 is installed
AND Package Information
crowbar-4.0+git.1528801103.f5708341-7.20 is installed
OR crowbar-core-4.0+git.1534246408.3ab19c567-9.33 is installed
OR crowbar-core-branding-upstream-4.0+git.1534246408.3ab19c567-9.33 is installed
OR crowbar-devel-4.0+git.1528801103.f5708341-7.20 is installed
OR crowbar-ha-4.0+git.1533750802.5768e73-4.34 is installed
OR crowbar-openstack-4.0+git.1534254269.ce598a9fe-9.39 is installed
OR crowbar-ui-1.1.0+git.1533844061.4ac8e723-4.3 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 8 is installed
AND Package Information
libjavascriptcoregtk-4_0-18-2.28.2-2.53 is installed
OR libwebkit2gtk-4_0-37-2.28.2-2.53 is installed
OR libwebkit2gtk3-lang-2.28.2-2.53 is installed
OR typelib-1_0-JavaScriptCore-4_0-2.28.2-2.53 is installed
OR typelib-1_0-WebKit2-4_0-2.28.2-2.53 is installed
OR webkit2gtk-4_0-injected-bundles-2.28.2-2.53 is installed
OR webkit2gtk3-2.28.2-2.53 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 8 is installed
AND python-cryptography-2.0.3-3.3 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 9 is installed
AND Package Information
mariadb-10.2.25-3.19 is installed
OR mariadb-galera-10.2.25-3.19 is installed
|