Oval Definition:oval:org.opensuse.security:def:60210
Revision Date:2020-12-01Version:1
Title:Security update for permissions (Moderate)
Description:

This update for permissions fixes the following issues:

Security issues fixed:

- CVE-2020-8013: Fixed an issue where chkstat set unintended setuid/capabilities for mrsh and wodim (bsc#1163922).

Non-security issues fixed:

- Fixed a regression where chkstat broke when /proc was not available (bsc#1160764, bsc#1160594). - Fixed capability handling when doing multiple permission changes at once (bsc#1161779).
Family:unixClass:patch
Status:Reference(s):1056061
1082885
1082975
1082977
1082991
1082998
1083002
1083250
1084656
1087026
1103737
1109663
1109847
1115375
1118900
1118987
1123886
1125721
1126455
1129622
1130675
1131955
1138459
1141780
1141782
1141783
1141784
1141785
1141786
1141787
1141789
1155787
1160594
1160764
1161779
1162197
1162200
1163922
1169511
896914
CVE-2004-0801
CVE-2009-0035
CVE-2009-0186
CVE-2010-4267
CVE-2011-2696
CVE-2011-2697
CVE-2011-2722
CVE-2012-5643
CVE-2013-1990
CVE-2013-1999
CVE-2013-4325
CVE-2013-6402
CVE-2013-6427
CVE-2014-0172
CVE-2014-10070
CVE-2014-10071
CVE-2014-10072
CVE-2014-7141
CVE-2014-7142
CVE-2014-9447
CVE-2014-9496
CVE-2014-9749
CVE-2014-9756
CVE-2015-0839
CVE-2015-5400
CVE-2015-7805
CVE-2015-8075
CVE-2016-10002
CVE-2016-10003
CVE-2016-10714
CVE-2016-2390
CVE-2016-2569
CVE-2016-2570
CVE-2016-2571
CVE-2016-2572
CVE-2016-3947
CVE-2016-3948
CVE-2016-4051
CVE-2016-4052
CVE-2016-4053
CVE-2016-4054
CVE-2016-4553
CVE-2016-4554
CVE-2016-4555
CVE-2016-4556
CVE-2016-7953
CVE-2017-13078
CVE-2017-13079
CVE-2017-13080
CVE-2017-13081
CVE-2017-13087
CVE-2017-13088
CVE-2017-18205
CVE-2017-18206
CVE-2017-2518
CVE-2017-7585
CVE-2017-7586
CVE-2017-7741
CVE-2017-7742
CVE-2017-8361
CVE-2017-8362
CVE-2017-8363
CVE-2017-8365
CVE-2018-1000802
CVE-2018-1071
CVE-2018-1083
CVE-2018-11805
CVE-2018-14424
CVE-2018-14647
CVE-2018-20815
CVE-2018-7549
CVE-2019-10160
CVE-2019-2745
CVE-2019-2762
CVE-2019-2766
CVE-2019-2769
CVE-2019-2786
CVE-2019-2816
CVE-2019-2842
CVE-2019-3812
CVE-2019-7317
CVE-2019-8934
CVE-2019-9824
CVE-2020-1930
CVE-2020-1931
CVE-2020-2756
CVE-2020-2757
CVE-2020-2773
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2830
CVE-2020-8013
SUSE-SU-2017:2745-1
SUSE-SU-2018:1072-1
SUSE-SU-2018:2527-1
SUSE-SU-2019:2036-1
SUSE-SU-2019:2053-2
SUSE-SU-2019:3050-1
SUSE-SU-2020:0810-1
SUSE-SU-2020:1571-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND signing-party-2.7-lp150.5 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • kconf_update5-5.32.0-7 is installed
  • OR kconfig-5.32.0-7 is installed
  • OR kconfig-devel-5.32.0-7 is installed
  • OR kconfig-devel-32bit-5.55.0-lp151.2.5 is installed
  • OR kconfig-devel-64bit-5.32.0-7 is installed
  • OR kdelibs4-4.14.33-7 is installed
  • OR kdelibs4-apidocs-4.14.33-7 is installed
  • OR kdelibs4-branding-upstream-4.14.33-7 is installed
  • OR kdelibs4-core-4.14.33-7 is installed
  • OR kdelibs4-doc-4.14.33-7 is installed
  • OR libKF5ConfigCore5-5.32.0-7 is installed
  • OR libKF5ConfigCore5-32bit-5.55.0-lp151.2.5 is installed
  • OR libKF5ConfigCore5-64bit-5.32.0-7 is installed
  • OR libKF5ConfigCore5-lang-5.32.0-7 is installed
  • OR libKF5ConfigGui5-5.32.0-7 is installed
  • OR libKF5ConfigGui5-32bit-5.55.0-lp151.2.5 is installed
  • OR libKF5ConfigGui5-64bit-5.32.0-7 is installed
  • OR libkde4-4.14.33-7 is installed
  • OR libkde4-32bit-4.14.38-lp151.9.5 is installed
  • OR libkde4-64bit-4.14.33-7 is installed
  • OR libkde4-devel-4.14.33-7 is installed
  • OR libkdecore4-4.14.33-7 is installed
  • OR libkdecore4-32bit-4.14.38-lp151.9.5 is installed
  • OR libkdecore4-64bit-4.14.33-7 is installed
  • OR libkdecore4-devel-4.14.33-7 is installed
  • OR libksuseinstall-devel-4.14.33-7 is installed
  • OR libksuseinstall1-4.14.33-7 is installed
  • OR libksuseinstall1-32bit-4.14.38-lp151.9.5 is installed
  • OR libksuseinstall1-64bit-4.14.33-7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND permissions-2015.09.28.1626-17.27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • elfutils-0.158-6 is installed
  • OR libasm1-0.158-6 is installed
  • OR libasm1-32bit-0.158-6 is installed
  • OR libdw1-0.158-6 is installed
  • OR libdw1-32bit-0.158-6 is installed
  • OR libebl1-0.158-6 is installed
  • OR libebl1-32bit-0.158-6 is installed
  • OR libelf1-0.158-6 is installed
  • OR libelf1-32bit-0.158-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.222-27.35 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_176-94_88-default-5-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_24-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • perl-Mail-SpamAssassin-3.4.2-44.8 is installed
  • OR spamassassin-3.4.2-44.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.82 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.82 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.82 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • dovecot22-2.2.31-19.11 is installed
  • OR dovecot22-backend-mysql-2.2.31-19.11 is installed
  • OR dovecot22-backend-pgsql-2.2.31-19.11 is installed
  • OR dovecot22-backend-sqlite-2.2.31-19.11 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • libsqlite3-0-3.8.10.2-9.15 is installed
  • OR libsqlite3-0-32bit-3.8.10.2-9.15 is installed
  • OR sqlite3-3.8.10.2-9.15 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND Package Information
  • ardana-ansible-9.0+git.1581611758.f694f7d-3.16 is installed
  • OR ardana-cinder-9.0+git.1579256229.c8b4b38-3.10 is installed
  • OR ardana-cobbler-9.0+git.1574950066.a3c4be4-3.10 is installed
  • OR ardana-db-9.0+git.1578936438.b9a9b95-3.16 is installed
  • OR ardana-horizon-9.0+git.1575562864.8ed5e10-3.13 is installed
  • OR ardana-input-model-9.0+git.1580403439.d425462-3.13 is installed
  • OR ardana-monasca-9.0+git.1579273481.4b8c46f-3.13 is installed
  • OR ardana-mq-9.0+git.1581024903.8e74867-3.10 is installed
  • OR ardana-nova-9.0+git.1580304673.6c668eb-3.16 is installed
  • OR ardana-octavia-9.0+git.1576074489.62de7e2-3.13 is installed
  • OR ardana-osconfig-9.0+git.1580235830.0dca223-3.13 is installed
  • OR ardana-tempest-9.0+git.1578932816.e299c08-3.10 is installed
  • OR ardana-tls-9.0+git.1575296665.3fdfe45-3.9 is installed
  • OR keepalived-2.0.19-3.3 is installed
  • OR openstack-barbican-7.0.1~dev24-3.6 is installed
  • OR openstack-barbican-api-7.0.1~dev24-3.6 is installed
  • OR openstack-barbican-keystone-listener-7.0.1~dev24-3.6 is installed
  • OR openstack-barbican-retry-7.0.1~dev24-3.6 is installed
  • OR openstack-barbican-worker-7.0.1~dev24-3.6 is installed
  • OR openstack-ceilometer-11.0.2~dev21-3.10 is installed
  • OR openstack-ceilometer-agent-central-11.0.2~dev21-3.10 is installed
  • OR openstack-ceilometer-agent-compute-11.0.2~dev21-3.10 is installed
  • OR openstack-ceilometer-agent-ipmi-11.0.2~dev21-3.10 is installed
  • OR openstack-ceilometer-agent-notification-11.0.2~dev21-3.10 is installed
  • OR openstack-ceilometer-polling-11.0.2~dev21-3.10 is installed
  • OR openstack-cinder-13.0.9~dev11-3.16 is installed
  • OR openstack-cinder-api-13.0.9~dev11-3.16 is installed
  • OR openstack-cinder-backup-13.0.9~dev11-3.16 is installed
  • OR openstack-cinder-scheduler-13.0.9~dev11-3.16 is installed
  • OR openstack-cinder-volume-13.0.9~dev11-3.16 is installed
  • OR openstack-dashboard-14.1.1~dev1-3.12 is installed
  • OR openstack-dashboard-theme-SUSE-2018.2+git.1555335229.5c8dec9-3.3 is installed
  • OR openstack-designate-7.0.1~dev23-3.13 is installed
  • OR openstack-designate-agent-7.0.1~dev23-3.13 is installed
  • OR openstack-designate-api-7.0.1~dev23-3.13 is installed
  • OR openstack-designate-central-7.0.1~dev23-3.13 is installed
  • OR openstack-designate-producer-7.0.1~dev23-3.13 is installed
  • OR openstack-designate-sink-7.0.1~dev23-3.13 is installed
  • OR openstack-designate-worker-7.0.1~dev23-3.13 is installed
  • OR openstack-heat-11.0.3~dev31-3.13 is installed
  • OR openstack-heat-api-11.0.3~dev31-3.13 is installed
  • OR openstack-heat-api-cfn-11.0.3~dev31-3.13 is installed
  • OR openstack-heat-engine-11.0.3~dev31-3.13 is installed
  • OR openstack-heat-plugin-heat_docker-11.0.3~dev31-3.13 is installed
  • OR openstack-horizon-plugin-designate-ui-7.0.1~dev8-3.6 is installed
  • OR openstack-horizon-plugin-ironic-ui-3.3.1~dev14-3.3 is installed
  • OR openstack-horizon-plugin-neutron-lbaas-ui-5.0.1~dev8-11 is installed
  • OR openstack-horizon-plugin-octavia-ui-2.0.2~dev1-1.3 is installed
  • OR openstack-ironic-11.1.4~dev22-3.13 is installed
  • OR openstack-ironic-api-11.1.4~dev22-3.13 is installed
  • OR openstack-ironic-conductor-11.1.4~dev22-3.13 is installed
  • OR openstack-ironic-python-agent-3.3.3~dev6-3.13 is installed
  • OR openstack-keystone-14.1.1~dev36-3.19 is installed
  • OR openstack-magnum-7.2.1~dev1-3.10 is installed
  • OR openstack-magnum-api-7.2.1~dev1-3.10 is installed
  • OR openstack-magnum-conductor-7.2.1~dev1-3.10 is installed
  • OR openstack-monasca-agent-2.8.1~dev13-3.6 is installed
  • OR openstack-neutron-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-dhcp-agent-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-fwaas-13.0.3~dev4-3.9 is installed
  • OR openstack-neutron-gbp-5.0.1~dev491-3.16 is installed
  • OR openstack-neutron-ha-tool-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-l3-agent-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-linuxbridge-agent-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-macvtap-agent-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-metadata-agent-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-metering-agent-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-openvswitch-agent-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-server-13.0.7~dev48-3.19 is installed
  • OR openstack-neutron-vpnaas-13.0.2~dev6-3.6 is installed
  • OR openstack-neutron-vyatta-agent-13.0.2~dev6-3.6 is installed
  • OR openstack-nova-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-api-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-cells-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-compute-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-conductor-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-console-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-novncproxy-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-placement-api-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-scheduler-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-serialproxy-18.2.4~dev63-3.19 is installed
  • OR openstack-nova-vncproxy-18.2.4~dev63-3.19 is installed
  • OR openstack-octavia-3.2.2~dev8-3.19 is installed
  • OR openstack-octavia-amphora-agent-3.2.2~dev8-3.19 is installed
  • OR openstack-octavia-amphora-image-0.1.2-7.6 is installed
  • OR openstack-octavia-amphora-image-x86_64-0.1.2-7.6 is installed
  • OR openstack-octavia-api-3.2.2~dev8-3.19 is installed
  • OR openstack-octavia-health-manager-3.2.2~dev8-3.19 is installed
  • OR openstack-octavia-housekeeping-3.2.2~dev8-3.19 is installed
  • OR openstack-octavia-worker-3.2.2~dev8-3.19 is installed
  • OR openstack-sahara-9.0.2~dev15-3.9 is installed
  • OR openstack-sahara-api-9.0.2~dev15-3.9 is installed
  • OR openstack-sahara-engine-9.0.2~dev15-3.9 is installed
  • OR openstack-swift-2.19.2~dev48-3.3 is installed
  • OR openstack-swift-account-2.19.2~dev48-3.3 is installed
  • OR openstack-swift-container-2.19.2~dev48-3.3 is installed
  • OR openstack-swift-object-2.19.2~dev48-3.3 is installed
  • OR openstack-swift-proxy-2.19.2~dev48-3.3 is installed
  • OR python-amqp-2.4.2-4.3 is installed
  • OR python-barbican-7.0.1~dev24-3.6 is installed
  • OR python-ceilometer-11.0.2~dev21-3.10 is installed
  • OR python-cinder-13.0.9~dev11-3.16 is installed
  • OR python-designate-7.0.1~dev23-3.13 is installed
  • OR python-heat-11.0.3~dev31-3.13 is installed
  • OR python-horizon-14.1.1~dev1-3.12 is installed
  • OR python-horizon-plugin-designate-ui-7.0.1~dev8-3.6 is installed
  • OR python-horizon-plugin-ironic-ui-3.3.1~dev14-3.3 is installed
  • OR python-horizon-plugin-neutron-lbaas-ui-5.0.1~dev8-11 is installed
  • OR python-horizon-plugin-octavia-ui-2.0.2~dev1-1.3 is installed
  • OR python-ironic-11.1.4~dev22-3.13 is installed
  • OR python-ironic-lib-2.14.2-3.3 is installed
  • OR python-keystone-14.1.1~dev36-3.19 is installed
  • OR python-keystoneauth1-3.10.1~dev10-3.3 is installed
  • OR python-keystoneclient-3.17.1~dev5-3.3 is installed
  • OR python-keystoneclient-doc-3.17.1~dev5-3.3 is installed
  • OR python-keystonemiddleware-5.2.2~dev3-14 is installed
  • OR python-magnum-7.2.1~dev1-3.10 is installed
  • OR python-monasca-agent-2.8.1~dev13-3.6 is installed
  • OR python-neutron-13.0.7~dev48-3.19 is installed
  • OR python-neutron-fwaas-13.0.3~dev4-3.9 is installed
  • OR python-neutron-gbp-5.0.1~dev491-3.16 is installed
  • OR python-neutron-vpnaas-13.0.2~dev6-3.6 is installed
  • OR python-nova-18.2.4~dev63-3.19 is installed
  • OR python-octavia-3.2.2~dev8-3.19 is installed
  • OR python-openstack_auth-14.1.1~dev1-3.12 is installed
  • OR python-ovs-2.9.0-3.3 is installed
  • OR python-sahara-9.0.2~dev15-3.9 is installed
  • OR python-swift-2.19.2~dev48-3.3 is installed
  • OR supportutils-plugin-suse-openstack-cloud-9.0.1574431436.987b47d-3.6 is installed
  • OR venv-openstack-barbican-7.0.1~dev24-3.15 is installed
  • OR venv-openstack-barbican-x86_64-7.0.1~dev24-3.15 is installed
  • OR venv-openstack-cinder-13.0.9~dev11-3.15 is installed
  • OR venv-openstack-cinder-x86_64-13.0.9~dev11-3.15 is installed
  • OR venv-openstack-designate-7.0.1~dev23-3.15 is installed
  • OR venv-openstack-designate-x86_64-7.0.1~dev23-3.15 is installed
  • OR venv-openstack-glance-17.0.1~dev30-3.13 is installed
  • OR venv-openstack-glance-x86_64-17.0.1~dev30-3.13 is installed
  • OR venv-openstack-heat-11.0.3~dev31-3.15 is installed
  • OR venv-openstack-heat-x86_64-11.0.3~dev31-3.15 is installed
  • OR venv-openstack-horizon-14.1.1~dev1-4.14 is installed
  • OR venv-openstack-horizon-x86_64-14.1.1~dev1-4.14 is installed
  • OR venv-openstack-ironic-11.1.4~dev22-4.11 is installed
  • OR venv-openstack-ironic-x86_64-11.1.4~dev22-4.11 is installed
  • OR venv-openstack-keystone-14.1.1~dev36-3.15 is installed
  • OR venv-openstack-keystone-x86_64-14.1.1~dev36-3.15 is installed
  • OR venv-openstack-magnum-7.2.1~dev1-4.15 is installed
  • OR venv-openstack-magnum-x86_64-7.2.1~dev1-4.15 is installed
  • OR venv-openstack-manila-7.3.1~dev15-3.15 is installed
  • OR venv-openstack-manila-x86_64-7.3.1~dev15-3.15 is installed
  • OR venv-openstack-monasca-2.7.1~dev10-3.13 is installed
  • OR venv-openstack-monasca-ceilometer-1.8.2~dev3-3.15 is installed
  • OR venv-openstack-monasca-ceilometer-x86_64-1.8.2~dev3-3.15 is installed
  • OR venv-openstack-monasca-x86_64-2.7.1~dev10-3.13 is installed
  • OR venv-openstack-neutron-13.0.7~dev48-6.15 is installed
  • OR venv-openstack-neutron-x86_64-13.0.7~dev48-6.15 is installed
  • OR venv-openstack-nova-18.2.4~dev63-3.15 is installed
  • OR venv-openstack-nova-x86_64-18.2.4~dev63-3.15 is installed
  • OR venv-openstack-octavia-3.2.2~dev8-4.15 is installed
  • OR venv-openstack-octavia-x86_64-3.2.2~dev8-4.15 is installed
  • OR venv-openstack-sahara-9.0.2~dev15-3.15 is installed
  • OR venv-openstack-sahara-x86_64-9.0.2~dev15-3.15 is installed
  • OR venv-openstack-swift-2.19.2~dev48-2.10 is installed
  • OR venv-openstack-swift-x86_64-2.19.2~dev48-2.10 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • java-1_7_0-openjdk-1.7.0.261-43.38 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.261-43.38 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.261-43.38 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.261-43.38 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND python-requests-2.20.1-4.3 is installed
  • BACK