Oval Definition:oval:org.opensuse.security:def:73675
Revision Date:2021-08-16Version:1
Title:Security update for cpio (Important)
Description:

This update for cpio fixes the following issues:

It was possible to trigger Remote code execution due to a integer overflow (CVE-2021-38185, bsc#1189206)

UPDATE: This update was buggy and could lead to hangs, so it has been retracted. There will be a follow up update.

Family:unixClass:patch
Status:Reference(s):1169063
1171899
1172906
1172935
1173197
1173606
1189206
CVE-2020-11647
CVE-2020-13164
CVE-2020-14093
CVE-2020-14154
CVE-2020-14954
CVE-2020-15466
CVE-2021-38185
SUSE-SU-2020:1771-1
SUSE-SU-2020:2144-1
SUSE-SU-2021:2689-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • wireshark-3.2.5-3.38 is installed
  • OR wireshark-devel-3.2.5-3.38 is installed
  • OR wireshark-ui-qt-3.2.5-3.38 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • mutt-1.10.1-3.8 is installed
  • OR mutt-doc-1.10.1-3.8 is installed
  • OR mutt-lang-1.10.1-3.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • cpio-2.12-3.6.1 is installed
  • OR cpio-lang-2.12-3.6.1 is installed
  • OR cpio-mt-2.12-3.6.1 is installed
  • BACK