Oval Definition:oval:org.opensuse.security:def:64475
Revision Date:2021-01-14Version:1
Title:Security update for open-iscsi (Important)
Description:

This update for open-iscsi fixes the following issues:

- Updated to upstream version 2.1.3 as 2.1.3-suse, for bsc#1179908, including: * uip: check for TCP urgent pointer past end of frame * uip: check for u8 overflow when processing TCP options * uip: check for header length underflow during checksum calculation * fwparam_ppc: Fix memory leak in fwparam_ppc.c * iscsiuio: Remove unused macro IFNAMSIZ defined in iscsid_ipc.c * fwparam_ppc: Fix illegal memory access in fwparam_ppc.c * sysfs: Verify parameter of sysfs_device_get() * fwparam_ppc: Fix NULL pointer dereference in find_devtree() * open-iscsi: Clean user_param list when process exit * iscsi_net_util: Fix NULL pointer dereference in find_vlan_dev() * open-iscsi: Fix NULL pointer dereference in mgmt_ipc_read_req() * open-iscsi: Fix invalid pointer deference in find_initiator() * iscsiuio: Fix invalid parameter when call fstat() * iscsi-iname: Verify open() return value before calling read() * iscsi_sysfs: Fix NULL pointer deference in iscsi_sysfs_read_iface

- Updatged to latest upstream, including: * iscsiadm: Optimize the the verification of mode paramters * iscsid: Poll timeout value to 1 minute for iscsid * iscsiadm: fix host stats mode coredump * iscsid: fix logging level when starting and shutting down daemon * Updated iscsiadm man page. * Fix memory leak in sysfs_get_str * libopeniscsiusr: Compare with max int instead of max long

- Systemd unit files should not depend on network.target (bsc#1179440).

- Updated to latest upstream, including async login ability: * Implement login 'no_wait' for iscsiadm NODE mode * iscsiadm buffer overflow regression when discovering many targets at once * iscsid: Check Invalid Session id for stop connection * Add ability to attempt target logins asynchronously

- %service_del_postun_without_restart is now available on SLE More accurately it's been introduced in SLE12-SP2+ and SLE15+
Family:unixClass:patch
Status:Reference(s):1142161
1146428
1151585
1160682
1167335
1167336
1167337
1169063
1169428
1170107
1171899
1171910
1171975
1172496
1173606
1174579
1177561
1177562
1177842
1179440
1179908
CVE-2010-0624
CVE-2013-2142
CVE-2016-5104
CVE-2016-6321
CVE-2018-20482
CVE-2019-13602
CVE-2019-13962
CVE-2019-14437
CVE-2019-14438
CVE-2019-14498
CVE-2019-14533
CVE-2019-14534
CVE-2019-14535
CVE-2019-14776
CVE-2019-14777
CVE-2019-14778
CVE-2019-14970
CVE-2019-16680
CVE-2019-20372
CVE-2019-9923
CVE-2020-10802
CVE-2020-10803
CVE-2020-10804
CVE-2020-11647
CVE-2020-11736
CVE-2020-13164
CVE-2020-15466
CVE-2020-15953
CVE-2020-26934
CVE-2020-26935
CVE-2020-6463
CVE-2020-6465
CVE-2020-6466
CVE-2020-6467
CVE-2020-6468
CVE-2020-6469
CVE-2020-6470
CVE-2020-6471
CVE-2020-6472
CVE-2020-6473
CVE-2020-6474
CVE-2020-6475
CVE-2020-6476
CVE-2020-6477
CVE-2020-6478
CVE-2020-6479
CVE-2020-6480
CVE-2020-6481
CVE-2020-6482
CVE-2020-6483
CVE-2020-6484
CVE-2020-6485
CVE-2020-6486
CVE-2020-6487
CVE-2020-6488
CVE-2020-6489
CVE-2020-6490
CVE-2020-6491
CVE-2020-6493
CVE-2020-6494
CVE-2020-6495
CVE-2020-6496
openSUSE-SU-2020:0204-1
openSUSE-SU-2020:0545-1
openSUSE-SU-2020:0823-1
openSUSE-SU-2020:0825-1
openSUSE-SU-2020:1188-1
openSUSE-SU-2020:1454-1
openSUSE-SU-2020:1806-1
SUSE-SU-2021:0127-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libwireshark13-3.2.5-lp151.2.12 is installed
  • OR libwiretap10-3.2.5-lp151.2.12 is installed
  • OR libwsutil11-3.2.5-lp151.2.12 is installed
  • OR wireshark-3.2.5-lp151.2.12 is installed
  • OR wireshark-devel-3.2.5-lp151.2.12 is installed
  • OR wireshark-ui-qt-3.2.5-lp151.2.12 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libetpan-1.9.4-lp152.3.3 is installed
  • OR libetpan-devel-1.9.4-lp152.3.3 is installed
  • OR libetpan20-1.9.4-lp152.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • iscsiuio-0.7.8.6-22.6.1 is installed
  • OR libopeniscsiusr0_2_0-2.1.3-22.6.1 is installed
  • OR open-iscsi-2.1.3-22.6.1 is installed
  • OR open-iscsi-devel-2.1.3-22.6.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • tar-1.30-3.3 is installed
  • OR tar-lang-1.30-3.3 is installed
  • OR tar-rmt-1.30-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed
  • AND Package Information
  • libimobiledevice-devel-1.2.0+git20170122.45fda81-1 is installed
  • OR libimobiledevice6-1.2.0+git20170122.45fda81-1 is installed
  • BACK