Oval Definition:oval:org.opensuse.security:def:67358
Revision Date:2021-12-16Version:1
Title:Security update for log4j (Important)
Description:

This update for log4j fixes the following issue:

- Previously published fixes for log4jshell turned out to be incomplete. Upstream has followed up on the original patch for CVE-2021-44228 with several additional changes (LOG4J2-3198, LOG4J2-3201, LOG4J2-3208, and LOG4J2-3211) that are included in this update. Since the totality of those patches is pretty much equivalent to an update to the latest version of log4j, we did update the package's tarball from version 2.13.0 to 2.16.0 instead of trying to apply those patches to the old version. This change brings in a new dependency on 'jakarta-servlet' and a version update of 'disruptor'. [bsc#1193743, CVE-2021-45046]
Family:unixClass:patch
Status:Reference(s):1160398
1169511
1171352
1175193
1175194
1193743
CVE-2020-14349
CVE-2020-14350
CVE-2020-2754
CVE-2020-2755
CVE-2020-2756
CVE-2020-2757
CVE-2020-2773
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2830
CVE-2021-44228
CVE-2021-45046
SUSE-SU-2020:1569-2
SUSE-SU-2020:2265-1
Platform(s):SUSE Linux Enterprise Module for Legacy Software 15 SP2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP3
SUSE Linux Enterprise Module for Server Applications 15 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Legacy Software 15 SP2 is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.252-3.35 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.252-3.35 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.252-3.35 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.252-3.35 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND Package Information
  • libecpg6-12.4-8.6 is installed
  • OR postgresql12-12.4-8.6 is installed
  • OR postgresql12-contrib-12.4-8.6 is installed
  • OR postgresql12-devel-12.4-8.6 is installed
  • OR postgresql12-docs-12.4-8.6 is installed
  • OR postgresql12-plperl-12.4-8.6 is installed
  • OR postgresql12-plpython-12.4-8.6 is installed
  • OR postgresql12-pltcl-12.4-8.6 is installed
  • OR postgresql12-server-12.4-8.6 is installed
  • OR postgresql12-server-devel-12.4-8.6 is installed
  • BACK