Oval Definition:oval:org.opensuse.security:def:74638
Revision Date:2021-06-02Version:1
Title:Security update for xstream (Important)
Description:

This update for xstream fixes the following issues:

- Upgrade to 1.4.16 - CVE-2021-21351: remote attacker to load and execute arbitrary code (bsc#1184796) - CVE-2021-21349: SSRF can lead to a remote attacker to request data from internal resources (bsc#1184797) - CVE-2021-21350: arbitrary code execution (bsc#1184380) - CVE-2021-21348: remote attacker could cause denial of service by consuming maximum CPU time (bsc#1184374) - CVE-2021-21347: remote attacker to load and execute arbitrary code from a remote host (bsc#1184378) - CVE-2021-21344: remote attacker could load and execute arbitrary code from a remote host (bsc#1184375) - CVE-2021-21342: server-side forgery (bsc#1184379) - CVE-2021-21341: remote attacker could cause a denial of service by allocating 100% CPU time (bsc#1184377) - CVE-2021-21346: remote attacker could load and execute arbitrary code (bsc#1184373) - CVE-2021-21345: remote attacker with sufficient rights could execute commands (bsc#1184372) - CVE-2021-21343: replace or inject objects, that result in the deletion of files on the local host (bsc#1184376)
Family:unixClass:patch
Status:Reference(s):1151867
1167090
1184372
1184373
1184374
1184375
1184376
1184377
1184378
1184379
1184380
1184796
1184797
CVE-2019-16707
CVE-2019-20503
CVE-2020-6422
CVE-2020-6424
CVE-2020-6425
CVE-2020-6426
CVE-2020-6427
CVE-2020-6428
CVE-2020-6429
CVE-2020-6449
CVE-2021-21341
CVE-2021-21342
CVE-2021-21343
CVE-2021-21344
CVE-2021-21345
CVE-2021-21346
CVE-2021-21347
CVE-2021-21348
CVE-2021-21349
CVE-2021-21350
CVE-2021-21351
openSUSE-SU-2020:0365-1
openSUSE-SU-2020:1717-1
SUSE-SU-2021:1840-1
Platform(s):openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Development Tools 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • hunspell-1.6.2-lp151.3.3 is installed
  • OR hunspell-devel-1.6.2-lp151.3.3 is installed
  • OR hunspell-devel-32bit-1.6.2-lp151.3.3 is installed
  • OR hunspell-tools-1.6.2-lp151.3.3 is installed
  • OR libhunspell-1_6-0-1.6.2-lp151.3.3 is installed
  • OR libhunspell-1_6-0-32bit-1.6.2-lp151.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Development Tools 15 SP2 is installed
  • AND xstream-1.4.16-3.8.1 is installed
  • BACK