Oval Definition:oval:org.opensuse.security:def:58114
Revision Date:2020-12-01Version:1
Title:Security update for Cloud7 packages (Moderate)
Description:

This update provides fixes for the following packages issues:

caasp-openstack-heat-templates:

- Update to version 1.0+git.1553079189.3bf8922: * SCRD-2813 Add support for CPI parameters - Update to version 1.0+git.1547562889.43707e7: * Switch LB protocol from HTTP to HTTPS

crowbar:

- Update to version 4.0+git.1551088848.823bcaa3: * install-chef-suse: filter comments from authorized_keys file

crowbar-core:

- Update to version 4.0+git.1556285635.ab602dd4d: * network: run wicked ifdown for interface cleanup (bsc#1063535) - Update to version 4.0+git.1554931881.d98412e0e: * Fix cloud-mkcloud9-job-backup-restore (SCRD-7126) - Update to version 4.0+git.1552239940.5bc9aaac4: * crowbar: Do not rely on Chef::Util::FileEdit to write the file (bsc#1127752) - Update to version 4.0+git.1550493400.9787ea9ad: * upgrade: Delay status switch after upgrade ends - Update to version 4.0+git.1549474445.d9a35cf52: * fix hound warning * Support RAID 0 - Packaged default upgrade timeouts file - Update to version 4.0+git.1549136953.afcde921f: * apache2: enable sslsessioncache - Update to version 4.0+git.1548859099.0edbbfdc2: * upgrade: Add default upgrade timeouts file

crowbar-ha:

- Update to version 4.0+git.1556181005.47c643d: * pacemaker: wait more for founder if SBD is configured (SCRD-8462) * pacemaker: don't check cluster members on founder (SCRD-8462) - Update to version 4.0+git.1554215159.8a42a71: * improve galera HA setup (bsc#1122875)

crowbar-openstack:

- Update to version 4.0+git.1554887450.ff7c30c1c: * neutron: Added option to use L3 HA with Keepalived - Update to version 4.0+git.1554843756.5622551da: * ironic: Fix regression in helper - Update to version 4.0+git.1554814630.ec3c89f25: * ceilometer: Install package which contains cron file (bsc#1130414) - Update to version 4.0+git.1551459192.89433e13b: * rabbit: fix mirroring regex - Update to version 4.0+git.1550582615.f6b433ec7: * ceilometer: Use pacemaker to handle expirer cron link (bsc#1113107) - Update to version 4.0+git.1550262335.9667fa580: * mysql: Do not set a custom logfile for mysqld (bsc#1112767) * mysql: create .my.cnf in root home directory for mysql cmdline - Update to version 4.0+git.1549986893.df836d6cc: * mariadb: Remove installing the xtrabackup package * ssl: Fix ACL setup in ssl_setup provider (bsc#1123709) galera-python-clustercheck:

- readtimeout.patch: Add socket read timeout (bsc#1122053)

openstack-ceilometer:

- Install openstack-ceilometer-expirer.cron into /usr/share/ceilometer This is needed in a clustered environment where multiple ceilometer-collector services are installed on different nodes (and due to that multiple expirer cron jobs installed). That can lead to deadlocks when the cron jobs run in parallel on the different nodes (bsc#1113107)

openstack-heat-gbp:

- switch to newton branch

python-PyKMIP:

- Fix a denial-of-service bug by setting the server socket timeout (bsc#1120767 CVE-2018-1000872)

python-pysaml2:

- Fix for the authentication bypass due to optimizations (CVE-2017-1000433, bsc#1074662)

rubygem-crowbar-client:

- Update to 3.9.0 - Add support for the restricted APIs - Add --raw to 'proposal show' and 'proposal edit' - Correctly parse error messages that we don't handle natively - Better upgrade repocheck output - Update to 3.7.0 - upgrade: Use cloud_version config for upgrade - ses: Add ses upload subcommand - Add cloud_version config field. - Wrap os-release file parsing for better reuse. - upgrade: Fix repocheck component in error message - upgrade: Better repocheck output - updated to version 3.6.1 * Hide the database step when it is not used (bsc#1118004) * Fix help strings * Describe how to upgrade more nodes with one command
Family:unixClass:patch
Status:Reference(s):1001367
1003800
1004477
1005555
1005558
1005562
1005564
1005566
1005569
1005581
1005582
1006539
1008318
1027519
1055695
1056278
1056280
1056281
1056282
1063535
1074662
1088268
1090036
1092885
1096223
1098735
1106383
1111498
1112767
1113107
1117025
1117382
1118004
1120658
1120767
1122000
1122053
1122344
1122875
1123333
1123709
1123892
1125352
1126140
1126141
1126192
1126195
1126196
1126198
1126201
1127400
1127558
1127752
1128954
1128987
1130414
1131053
1133495
1139083
1139459
1141670
1143797
1146874
1149813
1151021
1151377
1151506
1153674
1154043
1155574
1156482
1159814
1160305
1160498
1160968
1162108
1163019
1163933
1163985
1168140
1168142
1169392
1174543
985657
990890
CVE-2015-9542
CVE-2016-3189
CVE-2016-3492
CVE-2016-5584
CVE-2016-5624
CVE-2016-5626
CVE-2016-5629
CVE-2016-6663
CVE-2016-7440
CVE-2016-8283
CVE-2017-0861
CVE-2017-1000433
CVE-2017-14316
CVE-2017-14317
CVE-2017-14318
CVE-2017-14319
CVE-2018-1000199
CVE-2018-1000872
CVE-2018-11806
CVE-2018-12617
CVE-2018-3639
CVE-2019-12068
CVE-2019-12900
CVE-2019-14287
CVE-2019-14378
CVE-2019-14835
CVE-2019-15890
CVE-2019-17015
CVE-2019-17016
CVE-2019-17017
CVE-2019-17021
CVE-2019-17022
CVE-2019-17024
CVE-2019-17026
CVE-2019-17340
CVE-2019-17341
CVE-2019-17342
CVE-2019-17343
CVE-2019-17344
CVE-2019-17346
CVE-2019-17347
CVE-2019-17348
CVE-2019-6454
CVE-2020-11739
CVE-2020-11740
CVE-2020-11741
CVE-2020-11742
CVE-2020-1712
CVE-2020-1720
CVE-2020-2583
CVE-2020-2590
CVE-2020-2593
CVE-2020-2601
CVE-2020-2604
CVE-2020-2654
CVE-2020-2659
CVE-2020-8608
SUSE-SU-2016:2933-1
SUSE-SU-2017:2519-1
SUSE-SU-2018:1242-1
SUSE-SU-2018:2973-1
SUSE-SU-2019:0428-1
SUSE-SU-2019:1450-1
SUSE-SU-2019:1955-1
SUSE-SU-2019:2667-1
SUSE-SU-2019:2783-1
SUSE-SU-2020:0068-1
SUSE-SU-2020:0261-1
SUSE-SU-2020:0331-1
SUSE-SU-2020:0628-1
SUSE-SU-2020:0715-1
SUSE-SU-2020:1117-1
SUSE-SU-2020:2234-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND libpotrace0-1.15-lp150.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libmysqld-devel-10.2.29-lp151.2.9 is installed
  • OR libmysqld19-10.2.29-lp151.2.9 is installed
  • OR mariadb-10.2.29-lp151.2.9 is installed
  • OR mariadb-bench-10.2.29-lp151.2.9 is installed
  • OR mariadb-client-10.2.29-lp151.2.9 is installed
  • OR mariadb-errormessages-10.2.29-lp151.2.9 is installed
  • OR mariadb-galera-10.2.29-lp151.2.9 is installed
  • OR mariadb-test-10.2.29-lp151.2.9 is installed
  • OR mariadb-tools-10.2.29-lp151.2.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • java-1_7_0-openjdk-1.7.0.251-43.35 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.251-43.35 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.251-43.35 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.251-43.35 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • libmysqlclient18-10.0.28-17 is installed
  • OR libmysqlclient18-32bit-10.0.28-17 is installed
  • OR mariadb-10.0.28-17 is installed
  • OR mariadb-client-10.0.28-17 is installed
  • OR mariadb-errormessages-10.0.28-17 is installed
  • OR mariadb-tools-10.0.28-17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND sudo-1.8.10p3-10.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND ucode-intel-20180425-13.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • qemu-2.6.2-41.43 is installed
  • OR qemu-block-curl-2.6.2-41.43 is installed
  • OR qemu-block-rbd-2.6.2-41.43 is installed
  • OR qemu-block-ssh-2.6.2-41.43 is installed
  • OR qemu-guest-agent-2.6.2-41.43 is installed
  • OR qemu-ipxe-1.0.0-41.43 is installed
  • OR qemu-kvm-2.6.2-41.43 is installed
  • OR qemu-lang-2.6.2-41.43 is installed
  • OR qemu-ppc-2.6.2-41.43 is installed
  • OR qemu-s390-2.6.2-41.43 is installed
  • OR qemu-seabios-1.9.1-41.43 is installed
  • OR qemu-sgabios-8-41.43 is installed
  • OR qemu-tools-2.6.2-41.43 is installed
  • OR qemu-vgabios-1.9.1-41.43 is installed
  • OR qemu-x86-2.6.2-41.43 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND
  • kernel-default-4.4.180-94.100 is installed
  • OR kernel-default-base-4.4.180-94.100 is installed
  • OR kernel-default-devel-4.4.180-94.100 is installed
  • OR kernel-default-man-4.4.180-94.100 is installed
  • OR kernel-devel-4.4.180-94.100 is installed
  • OR kernel-macros-4.4.180-94.100 is installed
  • OR kernel-source-4.4.180-94.100 is installed
  • OR kernel-syms-4.4.180-94.100 is installed
  • OR kgraft-patch-4_4_180-94_100-default-1-4.3 is installed
  • OR kgraft-patch-SLE12-SP3_Update_27-1-4.3 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND
  • kernel-default-4.4.180-94.100 is installed
  • OR kernel-default-base-4.4.180-94.100 is installed
  • OR kernel-default-devel-4.4.180-94.100 is installed
  • OR kernel-default-man-4.4.180-94.100 is installed
  • OR kernel-devel-4.4.180-94.100 is installed
  • OR kernel-macros-4.4.180-94.100 is installed
  • OR kernel-source-4.4.180-94.100 is installed
  • OR kernel-syms-4.4.180-94.100 is installed
  • OR kgraft-patch-4_4_180-94_100-default-1-4.3 is installed
  • OR kgraft-patch-SLE12-SP3_Update_27-1-4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • MozillaFirefox-52.2.0esr-108 is installed
  • OR MozillaFirefox-translations-52.2.0esr-108 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • dbus-1-1.8.22-29.17 is installed
  • OR dbus-1-x11-1.8.22-29.17 is installed
  • OR libdbus-1-3-1.8.22-29.17 is installed
  • OR libdbus-1-3-32bit-1.8.22-29.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_180-94_100-default-2-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_27-2-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libexif-0.6.22-8.9 is installed
  • OR libexif12-0.6.22-8.9 is installed
  • OR libexif12-32bit-0.6.22-8.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.126 is installed
  • OR ImageMagick-config-6-SUSE-6.8.8.1-71.126 is installed
  • OR ImageMagick-config-6-upstream-6.8.8.1-71.126 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.126 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.126 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • DirectFB-1.7.1-6 is installed
  • OR lib++dfb-1_7-1-1.7.1-6 is installed
  • OR libdirectfb-1_7-1-1.7.1-6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • caasp-openstack-heat-templates-1.0+git.1553079189.3bf8922-1.6 is installed
  • OR crowbar-4.0+git.1551088848.823bcaa3-7.29 is installed
  • OR crowbar-core-4.0+git.1556285635.ab602dd4d-9.46 is installed
  • OR crowbar-core-branding-upstream-4.0+git.1556285635.ab602dd4d-9.46 is installed
  • OR crowbar-devel-4.0+git.1551088848.823bcaa3-7.29 is installed
  • OR crowbar-ha-4.0+git.1556181005.47c643d-4.46 is installed
  • OR crowbar-openstack-4.0+git.1554887450.ff7c30c1c-9.51 is installed
  • OR galera-python-clustercheck-0.0+git.1506329536.8f5878c-1.6 is installed
  • OR openstack-ceilometer-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-agent-central-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-agent-compute-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-agent-ipmi-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-agent-notification-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-api-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-collector-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-doc-7.1.1~dev4-4.15 is installed
  • OR openstack-ceilometer-polling-7.1.1~dev4-4.15 is installed
  • OR openstack-heat-gbp-5.1.1~dev1-2.6 is installed
  • OR python-PyKMIP-0.5.0-3.3 is installed
  • OR python-ceilometer-7.1.1~dev4-4.15 is installed
  • OR python-heat-gbp-5.1.1~dev1-2.6 is installed
  • OR python-pysaml2-4.0.2-3.6 is installed
  • OR ruby2.1-rubygem-crowbar-client-3.9.0-7.14 is installed
  • OR rubygem-crowbar-client-3.9.0-7.14 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND python-Twisted-15.2.1-9.8 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND couchdb-1.7.2-3.3 is installed
  • BACK