Oval Definition:oval:org.opensuse.security:def:60763
Revision Date:2020-12-01Version:1
Title:Security update for shim (Moderate)
Description:

This update for shim fixes the following issues:

- Update to the unified shim binary from SUSE Linux Enterprise 15-SP1 (bsc#1168994)

This update addresses the 'BootHole' security issue (master CVE CVE-2020-10713), by disallowing binaries signed by the previous SUSE UEFI signing key from booting.

This update should only be installed after updates of grub2, the Linux kernel and (if used) Xen from July / August 2020 are applied.

Additional fixes:

+ shim-install: install MokManager to \EFI\boot to process the pending MOK request (bsc#1175626, bsc#1175656)

Family:unixClass:patch
Status:Reference(s):1050257
1051188
1060995
1060996
1061000
1072928
1076503
1077358
1092952
1093095
1095070
1099510
1101288
1111789
1117740
1120629
1120630
1120631
1123022
1124593
1127155
1128829
1128963
1130116
1131823
1137977
1155787
1167890
1168630
1168930
1168994
1173144
1173991
1174284
1174628
1175626
1175656
1175686
1177943
925502
995352
CVE-2015-2775
CVE-2016-1000031
CVE-2016-6893
CVE-2017-11591
CVE-2017-11683
CVE-2017-14859
CVE-2017-14862
CVE-2017-14864
CVE-2017-17669
CVE-2017-2518
CVE-2018-0618
CVE-2018-10958
CVE-2018-10998
CVE-2018-11531
CVE-2018-13796
CVE-2018-19622
CVE-2018-19623
CVE-2018-19624
CVE-2018-19625
CVE-2018-19626
CVE-2018-19627
CVE-2018-20532
CVE-2018-20533
CVE-2018-20534
CVE-2018-5764
CVE-2018-5950
CVE-2019-3814
CVE-2019-7164
CVE-2019-7524
CVE-2019-7548
CVE-2020-10713
CVE-2020-14344
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14798
CVE-2020-14803
CVE-2020-15663
CVE-2020-15664
CVE-2020-15670
CVE-2020-5260
CVE-2020-6819
CVE-2020-6820
CVE-2020-8163
SUSE-SU-2018:0174-1
SUSE-SU-2019:0900-1
SUSE-SU-2019:1214-1
SUSE-SU-2019:2261-1
SUSE-SU-2019:3050-1
SUSE-SU-2020:0928-1
SUSE-SU-2020:0992-1
SUSE-SU-2020:2117-1
SUSE-SU-2020:2140-1
SUSE-SU-2020:2627-1
SUSE-SU-2020:2660-1
SUSE-SU-2020:3310-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • chromedriver-70.0.3538.102-lp150.2.23 is installed
  • OR chromium-70.0.3538.102-lp150.2.23 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • chromedriver-76.0.3809.132-lp151.2.25 is installed
  • OR chromium-76.0.3809.132-lp151.2.25 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • tomcat-9.0.36-lp152.2.3 is installed
  • OR tomcat-admin-webapps-9.0.36-lp152.2.3 is installed
  • OR tomcat-docs-webapp-9.0.36-lp152.2.3 is installed
  • OR tomcat-el-3_0-api-9.0.36-lp152.2.3 is installed
  • OR tomcat-embed-9.0.36-lp152.2.3 is installed
  • OR tomcat-javadoc-9.0.36-lp152.2.3 is installed
  • OR tomcat-jsp-2_3-api-9.0.36-lp152.2.3 is installed
  • OR tomcat-jsvc-9.0.36-lp152.2.3 is installed
  • OR tomcat-lib-9.0.36-lp152.2.3 is installed
  • OR tomcat-servlet-4_0-api-9.0.36-lp152.2.3 is installed
  • OR tomcat-webapps-9.0.36-lp152.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND rsync-3.1.0-13.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libX11-1.6.2-12.8 is installed
  • OR libX11-6-1.6.2-12.8 is installed
  • OR libX11-6-32bit-1.6.2-12.8 is installed
  • OR libX11-data-1.6.2-12.8 is installed
  • OR libX11-xcb1-1.6.2-12.8 is installed
  • OR libX11-xcb1-32bit-1.6.2-12.8 is installed
  • OR libxcb-1.10-4.5 is installed
  • OR libxcb-dri2-0-1.10-4.5 is installed
  • OR libxcb-dri2-0-32bit-1.10-4.5 is installed
  • OR libxcb-dri3-0-1.10-4.5 is installed
  • OR libxcb-dri3-0-32bit-1.10-4.5 is installed
  • OR libxcb-glx0-1.10-4.5 is installed
  • OR libxcb-glx0-32bit-1.10-4.5 is installed
  • OR libxcb-present0-1.10-4.5 is installed
  • OR libxcb-present0-32bit-1.10-4.5 is installed
  • OR libxcb-randr0-1.10-4.5 is installed
  • OR libxcb-render0-1.10-4.5 is installed
  • OR libxcb-render0-32bit-1.10-4.5 is installed
  • OR libxcb-shape0-1.10-4.5 is installed
  • OR libxcb-shm0-1.10-4.5 is installed
  • OR libxcb-shm0-32bit-1.10-4.5 is installed
  • OR libxcb-sync1-1.10-4.5 is installed
  • OR libxcb-sync1-32bit-1.10-4.5 is installed
  • OR libxcb-xf86dri0-1.10-4.5 is installed
  • OR libxcb-xfixes0-1.10-4.5 is installed
  • OR libxcb-xfixes0-32bit-1.10-4.5 is installed
  • OR libxcb-xinerama0-1.10-4.5 is installed
  • OR libxcb-xkb1-1.10-4.5 is installed
  • OR libxcb-xkb1-32bit-1.10-4.5 is installed
  • OR libxcb-xv0-1.10-4.5 is installed
  • OR libxcb1-1.10-4.5 is installed
  • OR libxcb1-32bit-1.10-4.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • MozillaFirefox-78.2.0-112.19 is installed
  • OR MozillaFirefox-devel-78.2.0-112.19 is installed
  • OR MozillaFirefox-translations-common-78.2.0-112.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libsolv-0.6.36-2.30 is installed
  • OR libsolv-devel-0.6.36-2.30 is installed
  • OR libsolv-tools-0.6.36-2.30 is installed
  • OR perl-solv-0.6.36-2.30 is installed
  • OR python-solv-0.6.36-2.30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • exiv2-0.23-12.5 is installed
  • OR libexiv2-12-0.23-12.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • giflib-progs-5.0.5-12 is installed
  • OR libgif6-5.0.5-12 is installed
  • OR libgif6-32bit-5.0.5-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • xorg-x11-server-1.19.6-4.11 is installed
  • OR xorg-x11-server-extra-1.19.6-4.11 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND shim-15+git47-25.11 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND python-urllib3-1.23-3.6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND python-SQLAlchemy-1.1.12-3.5 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • libX11-1.6.2-12.12 is installed
  • OR libX11-6-1.6.2-12.12 is installed
  • OR libX11-6-32bit-1.6.2-12.12 is installed
  • OR libX11-data-1.6.2-12.12 is installed
  • OR libX11-xcb1-1.6.2-12.12 is installed
  • OR libX11-xcb1-32bit-1.6.2-12.12 is installed
  • BACK