Oval Definition:oval:org.opensuse.security:def:58465
Revision Date:2020-12-01Version:1
Title:Security update for sudo (Important)
Description:

This update for sudo fixes the following security issue:

- CVE-2017-1000368: A follow-up fix to CVE-2017-1000367, the Linux process name could also contain a newline, which could be used to trick sudo to read/write to an arbitrary open terminal. (bsc#1042146)

Also the following non security bug was fixed:

- Link the 'system_group' plugin with sudo_util library to resolve the missing sudo_dso_findsym symbol (bsc#1034560)

Family:unixClass:patch
Status:Reference(s):1000662
1034560
1038505
1042146
1046853
1046858
1057389
1065274
1070727
1084632
1087082
1087083
1089343
1104134
1106119
1116574
1122293
1122299
1123886
1131060
1136446
1137597
1140747
1160594
1160764
1161779
1163922
1168994
1171252
1171254
1172437
1173027
1173812
1174463
1174570
CVE-2016-9840
CVE-2016-9841
CVE-2016-9842
CVE-2016-9843
CVE-2017-1000251
CVE-2017-1000368
CVE-2017-10684
CVE-2017-10685
CVE-2017-1289
CVE-2017-15088
CVE-2017-17083
CVE-2017-17084
CVE-2017-17085
CVE-2017-3509
CVE-2017-3511
CVE-2017-3533
CVE-2017-3539
CVE-2017-3544
CVE-2018-11212
CVE-2018-13785
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3183
CVE-2018-3214
CVE-2018-3639
CVE-2018-3640
CVE-2018-3646
CVE-2019-11477
CVE-2019-11478
CVE-2019-2422
CVE-2019-3846
CVE-2019-3880
CVE-2020-10713
CVE-2020-10757
CVE-2020-12653
CVE-2020-12654
CVE-2020-14308
CVE-2020-14309
CVE-2020-14310
CVE-2020-14311
CVE-2020-15706
CVE-2020-15707
CVE-2020-8013
CVE-2020-8177
SUSE-SU-2017:1386-1
SUSE-SU-2017:1626-1
SUSE-SU-2017:1815-1
SUSE-SU-2017:2521-1
SUSE-SU-2017:2948-1
SUSE-SU-2017:3436-1
SUSE-SU-2018:2331-1
SUSE-SU-2018:4064-1
SUSE-SU-2019:0604-1
SUSE-SU-2019:1195-1
SUSE-SU-2020:0545-1
SUSE-SU-2020:2076-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • gstreamer-plugins-bad-1.12.5-lp150.1 is installed
  • OR gstreamer-plugins-bad-lang-1.12.5-lp150.1 is installed
  • OR libgstadaptivedemux-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstbadaudio-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstbadbase-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstbadvideo-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstbasecamerabinsrc-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstcodecparsers-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstgl-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstmpegts-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstphotography-1_0-0-1.12.5-lp150.1 is installed
  • OR libgsturidownloader-1_0-0-1.12.5-lp150.1 is installed
  • OR libgstwayland-1_0-0-1.12.5-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • kernel-debug-4.12.14-lp151.28.4 is installed
  • OR kernel-debug-base-4.12.14-lp151.28.4 is installed
  • OR kernel-debug-devel-4.12.14-lp151.28.4 is installed
  • OR kernel-default-4.12.14-lp151.28.4 is installed
  • OR kernel-default-base-4.12.14-lp151.28.4 is installed
  • OR kernel-default-devel-4.12.14-lp151.28.4 is installed
  • OR kernel-devel-4.12.14-lp151.28.4 is installed
  • OR kernel-docs-4.12.14-lp151.28.4 is installed
  • OR kernel-docs-html-4.12.14-lp151.28.4 is installed
  • OR kernel-kvmsmall-4.12.14-lp151.28.4 is installed
  • OR kernel-kvmsmall-base-4.12.14-lp151.28.4 is installed
  • OR kernel-kvmsmall-devel-4.12.14-lp151.28.4 is installed
  • OR kernel-macros-4.12.14-lp151.28.4 is installed
  • OR kernel-obs-build-4.12.14-lp151.28.4 is installed
  • OR kernel-obs-qa-4.12.14-lp151.28.4 is installed
  • OR kernel-source-4.12.14-lp151.28.4 is installed
  • OR kernel-source-vanilla-4.12.14-lp151.28.4 is installed
  • OR kernel-syms-4.12.14-lp151.28.4 is installed
  • OR kernel-vanilla-4.12.14-lp151.28.4 is installed
  • OR kernel-vanilla-base-4.12.14-lp151.28.4 is installed
  • OR kernel-vanilla-devel-4.12.14-lp151.28.4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND sudo-1.8.10p3-10.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • libdcerpc-atsvc0-4.2.4-28.32 is installed
  • OR samba-4.2.4-28.32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_121-92_101-default-4-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_27-4-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND ucode-intel-20180807-13.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND dnsmasq-2.76-17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND sudo-1.8.20p2-3.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND mailman-2.1.17-3.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_175-94_79-default-6-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_23-6-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • openssh-7.2p2-74.42 is installed
  • OR openssh-askpass-gnome-7.2p2-74.42 is installed
  • OR openssh-fips-7.2p2-74.42 is installed
  • OR openssh-helpers-7.2p2-74.42 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • elfutils-0.158-6 is installed
  • OR libasm1-0.158-6 is installed
  • OR libasm1-32bit-0.158-6 is installed
  • OR libdw1-0.158-6 is installed
  • OR libdw1-32bit-0.158-6 is installed
  • OR libebl1-0.158-6 is installed
  • OR libebl1-32bit-0.158-6 is installed
  • OR libelf-devel-0.158-6 is installed
  • OR libelf1-0.158-6 is installed
  • OR libelf1-32bit-0.158-6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND cobbler-2.6.6-49.9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libpython3_4m1_0-3.4.6-25.29 is installed
  • OR python3-3.4.6-25.29 is installed
  • OR python3-base-3.4.6-25.29 is installed
  • OR python3-curses-3.4.6-25.29 is installed
  • BACK