Oval Definition:oval:org.opensuse.security:def:94166
Revision Date:2021-06-02Version:1
Title: (Important)
Description:

This update for xstream fixes the following issues:

- Upgrade to 1.4.16 - CVE-2021-21351: remote attacker to load and execute arbitrary code (bsc#1184796) - CVE-2021-21349: SSRF can lead to a remote attacker to request data from internal resources (bsc#1184797) - CVE-2021-21350: arbitrary code execution (bsc#1184380) - CVE-2021-21348: remote attacker could cause denial of service by consuming maximum CPU time (bsc#1184374) - CVE-2021-21347: remote attacker to load and execute arbitrary code from a remote host (bsc#1184378) - CVE-2021-21344: remote attacker could load and execute arbitrary code from a remote host (bsc#1184375) - CVE-2021-21342: server-side forgery (bsc#1184379) - CVE-2021-21341: remote attacker could cause a denial of service by allocating 100% CPU time (bsc#1184377) - CVE-2021-21346: remote attacker could load and execute arbitrary code (bsc#1184373) - CVE-2021-21345: remote attacker with sufficient rights could execute commands (bsc#1184372) - CVE-2021-21343: replace or inject objects, that result in the deletion of files on the local host (bsc#1184376)
Family:unixClass:patch
Status:Reference(s):1184372
1184373
1184374
1184375
1184376
1184377
1184378
1184379
1184380
1184796
1184797
CVE-2019-3691
CVE-2021-21341
CVE-2021-21342
CVE-2021-21343
CVE-2021-21344
CVE-2021-21345
CVE-2021-21346
CVE-2021-21347
CVE-2021-21348
CVE-2021-21349
CVE-2021-21350
CVE-2021-21351
Platform(s):Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for High Performance Computing 15 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for High Performance Computing 15 SP2 is installed
  • AND Package Information
  • libmunge2-0.5.14-4.9.1 is installed
  • OR munge-0.5.14-4.9.1 is installed
  • OR munge-devel-0.5.14-4.9.1 is installed
  • Definition Synopsis
  • Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2 is installed
  • AND xstream-1.4.16-3.8.1 is installed
  • BACK