Oval Definition:oval:org.opensuse.security:def:73864
Revision Date:2021-08-16Version:1
Title:Security update for cpio (Important)
Description:

This update for cpio fixes the following issues:

It was possible to trigger Remote code execution due to a integer overflow (CVE-2021-38185, bsc#1189206)

UPDATE: This update was buggy and could lead to hangs, so it has been retracted. There will be a follow up update.

Family:unixClass:patch
Status:Reference(s):1084929
1172402
1189206
CVE-2020-12405
CVE-2020-12406
CVE-2020-12410
CVE-2021-38185
SUSE-SU-2021:2689-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Basesystem 15 SP3
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
  • AND Package Information
  • MozillaFirefox-68.9.0-3.91 is installed
  • OR MozillaFirefox-branding-upstream-68.9.0-3.91 is installed
  • OR MozillaFirefox-buildsymbols-68.9.0-3.91 is installed
  • OR MozillaFirefox-devel-68.9.0-3.91 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
  • AND Package Information
  • cpio-2.12-3.6.1 is installed
  • OR cpio-lang-2.12-3.6.1 is installed
  • OR cpio-mt-2.12-3.6.1 is installed
  • BACK