openSUSE Recommended Update: Recommended update for lvm2
______________________________________________________________________________
Announcement ID: openSUSE-RU-2017:2610-1
Rating: moderate
References: #1028485 #1045628 #978055 #998893 #999878
Affected Products:
openSUSE Leap 42.3
openSUSE Leap 42.2
______________________________________________________________________________
An update that has 5 recommended fixes can now be installed.
Description:
This update for lvm2 provides the following fixes:
- Create /dev/disk/by-part{label,uuid} and gpt-auto-root links.
(bsc#1028485)
- Try to refresh clvmd's device cache on the first failure. (bsc#978055)
- Fix stale device cache in clvmd. (bsc#978055)
- Warn if PV size in metadata is larger than disk device size. (bsc#999878)
- Fix lvm2 activation issue when used on top of multipath. (bsc#998893)
This update was imported from the SUSE:SLE-12-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-1108=1
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-1108=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
device-mapper-1.02.97-77.1
device-mapper-debuginfo-1.02.97-77.1
device-mapper-devel-1.02.97-77.1
lvm2-2.02.120-77.1
lvm2-clvm-2.02.120-77.1
lvm2-clvm-debuginfo-2.02.120-77.1
lvm2-cmirrord-2.02.120-77.1
lvm2-cmirrord-debuginfo-2.02.120-77.1
lvm2-debuginfo-2.02.120-77.1
lvm2-debugsource-2.02.120-77.1
lvm2-devel-2.02.120-77.1
- openSUSE Leap 42.3 (x86_64):
device-mapper-32bit-1.02.97-77.1
device-mapper-debuginfo-32bit-1.02.97-77.1
device-mapper-devel-32bit-1.02.97-77.1
- openSUSE Leap 42.2 (i586 x86_64):
device-mapper-1.02.97-73.6.1
device-mapper-debuginfo-1.02.97-73.6.1
device-mapper-devel-1.02.97-73.6.1
lvm2-2.02.120-73.6.1
lvm2-clvm-2.02.120-73.6.1
lvm2-clvm-debuginfo-2.02.120-73.6.1
lvm2-cmirrord-2.02.120-73.6.1
lvm2-cmirrord-debuginfo-2.02.120-73.6.1
lvm2-debuginfo-2.02.120-73.6.1
lvm2-debugsource-2.02.120-73.6.1
lvm2-devel-2.02.120-73.6.1
- openSUSE Leap 42.2 (x86_64):
device-mapper-32bit-1.02.97-73.6.1
device-mapper-debuginfo-32bit-1.02.97-73.6.1
device-mapper-devel-32bit-1.02.97-73.6.1
References:
https://bugzilla.suse.com/1028485https://bugzilla.suse.com/1045628https://bugzilla.suse.com/978055https://bugzilla.suse.com/998893https://bugzilla.suse.com/999878
openSUSE Recommended Update: Recommended update for tigervnc
______________________________________________________________________________
Announcement ID: openSUSE-RU-2017:2609-1
Rating: low
References: #1041847 #1053373 #1054300
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that has three recommended fixes can now be
installed.
Description:
This update for tigervnc provides the following fixes:
- Fix race problem when detecting listening inetd sockets. (bsc#1054300)
- Fix certificate handling in the Java client. (bsc#1041847)
- Make sure CN in generated certificate doesn't exceed 64 characters.
(bsc#1041847)
- Change with-vnc-key.sh to generate TLS certificate using current
hostname to keep it short. (bsc#1041847)
- Disable MIT-SHM extension when running under user "vnc". (bsc#1053373)
This update was imported from the SUSE:SLE-12-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-1105=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
libXvnc-devel-1.6.0-21.1
libXvnc1-1.6.0-21.1
libXvnc1-debuginfo-1.6.0-21.1
tigervnc-1.6.0-21.1
tigervnc-debuginfo-1.6.0-21.1
tigervnc-debugsource-1.6.0-21.1
xorg-x11-Xvnc-1.6.0-21.1
xorg-x11-Xvnc-debuginfo-1.6.0-21.1
References:
https://bugzilla.suse.com/1041847https://bugzilla.suse.com/1053373https://bugzilla.suse.com/1054300
openSUSE Recommended Update: Recommended update for autofs
______________________________________________________________________________
Announcement ID: openSUSE-RU-2017:2608-1
Rating: low
References: #1046493
Affected Products:
openSUSE Leap 42.3
openSUSE Leap 42.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for autofs improves timeout handling to use a monotonic time
source. This prevents negative adjustments of the system clock from
affecting expiration of automounted volumes.
This update was imported from the SUSE:SLE-12-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-1109=1
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-1109=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
autofs-5.0.9-19.1
autofs-debuginfo-5.0.9-19.1
autofs-debugsource-5.0.9-19.1
- openSUSE Leap 42.2 (i586 x86_64):
autofs-5.0.9-15.6.1
autofs-debuginfo-5.0.9-15.6.1
autofs-debugsource-5.0.9-15.6.1
References:
https://bugzilla.suse.com/1046493
openSUSE Recommended Update: Recommended update for spec-cleaner
______________________________________________________________________________
Announcement ID: openSUSE-RU-2017:2606-1
Rating: low
References: #1060402
Affected Products:
openSUSE Leap 42.3
openSUSE Leap 42.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for spec-cleaner provides version 1.0.0 and fixes the
following issues:
- Recognize the BuildConflicts tag.
- Fix few make parsing errors.
- Fix some codeblock error detection.
- More path replacements detection.
- Keep uppercase URL tag as per vote.
- Include pkgconfig and others from leap 42.3 instead of 42.2.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-1107=1
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-1107=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.3 (noarch):
spec-cleaner-1.0.0-34.1
spec-cleaner-format_spec_file-1.0.0-34.1
- openSUSE Leap 42.2 (noarch):
spec-cleaner-1.0.0-31.12.1
spec-cleaner-format_spec_file-1.0.0-31.12.1
References:
https://bugzilla.suse.com/1060402
openSUSE Recommended Update: Recommended update for python-openqa_review
______________________________________________________________________________
Announcement ID: openSUSE-RU-2017:2605-1
Rating: moderate
References: #1059661
Affected Products:
openSUSE Leap 42.3
openSUSE Leap 42.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for python-openqa_review to version 1.7.5 contains the
following fixes:
- Support more recent openQA web structure (boo#1059661)
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-1103=1
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-1103=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.3 (noarch):
python-openqa_review-1.7.5-3.1
- openSUSE Leap 42.2 (noarch):
python-openqa_review-1.7.5-5.6.1
References:
https://bugzilla.suse.com/1059661
openSUSE Security Update: Security update for spice
______________________________________________________________________________
Announcement ID: openSUSE-SU-2017:2604-1
Rating: important
References: #1046779
Cross-References: CVE-2017-7506
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for spice fixes the following security issues:
- CVE-2017-7506: Fixed an out-of-bounds memory access when processing
specially crafted messages from authenticated attacker to the spice
server resulting into crash and/or server memory leak (bsc#1046779).
This update was imported from the SUSE:SLE-12-SP3:Update update project.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-1110=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.3 (x86_64):
libspice-server-devel-0.12.8-3.1
libspice-server1-0.12.8-3.1
libspice-server1-debuginfo-0.12.8-3.1
spice-debugsource-0.12.8-3.1
References:
https://www.suse.com/security/cve/CVE-2017-7506.htmlhttps://bugzilla.suse.com/1046779
openSUSE Recommended Update: Recommended update for vsftpd
______________________________________________________________________________
Announcement ID: openSUSE-RU-2017:2603-1
Rating: moderate
References: #1042137 #1044292 #1048427 #1052900
Affected Products:
openSUSE Leap 42.3
openSUSE Leap 42.2
______________________________________________________________________________
An update that has four recommended fixes can now be
installed.
Description:
This update for vsftpd provides the following fixes:
- Fix a bug in vsftpd that would cause SSL protocol errors, aborting the
connection, whenever system errors occurred that were supposed to be
non-fatal. (bsc#1044292)
- Fix a seccomp failure that happens in FIPS mode when SSL is enabled.
(bsc#1052900)
- Allow the FTP server to append to a file system pipe. (bsc#1048427)
- Create a new configuration option "address_space_limit", which
determines the memory limit vsftpd configures for its own process (given
in bytes). The previously hard-coded limit (100 MB) may not be
sufficient for vsftpd servers running with certain PAM modules enabled,
and in such cases administrators may wish to raise the limit to match
their system's requirements. (bsc#1042137)
This update was imported from the SUSE:SLE-12:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-1106=1
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-1106=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
vsftpd-3.0.2-25.1
vsftpd-debuginfo-3.0.2-25.1
vsftpd-debugsource-3.0.2-25.1
- openSUSE Leap 42.2 (i586 x86_64):
vsftpd-3.0.2-21.6.1
vsftpd-debuginfo-3.0.2-21.6.1
vsftpd-debugsource-3.0.2-21.6.1
References:
https://bugzilla.suse.com/1042137https://bugzilla.suse.com/1044292https://bugzilla.suse.com/1048427https://bugzilla.suse.com/1052900
openSUSE Recommended Update: Recommended update for drbd-utils
______________________________________________________________________________
Announcement ID: openSUSE-RU-2017:2602-1
Rating: low
References: #1025585 #1032074 #1037109 #1048671 #1052352
Affected Products:
openSUSE Leap 42.2
______________________________________________________________________________
An update that has 5 recommended fixes can now be installed.
Description:
This update for drbd-utils provides the following fixes:
- Fix propagation of full bitmap by drbdmeta. (bsc#1037109)
- Wait-for-* return success if there are no peers.
- Naturally align 64 bit attributes in gennetlink packet.
- Improve systemd unit-file to wait for network-online.target.
- Allow to pass peer device options on the drbdadm command-line.
- Fix drbdadm net-options by not passing the transport.
- Allow partial adjust by --skip-disk and/or --skip-net.
- Support for a new meta-data flag that helps resize operations.
- Drbdadm resize waits until new new size is user visible.
- Support for the reload operation in the OCF resource agent.
- Fix inconsistent external md when upgrade v8 to v9. (bsc#1032074)
- Make sure the legacy xmdomain.cfg configuration format works properly
fixing the usage
of libvirt and xen. (bsc#1052352)
- Fix the stacking of resources on handlers like "before-resync-target"
when called from kernel space. (bsc#1048671)
This update was imported from the SUSE:SLE-12-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-1104=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.2 (i586 x86_64):
drbd-utils-8.9.8-4.6.1
drbd-utils-debuginfo-8.9.8-4.6.1
drbd-utils-debugsource-8.9.8-4.6.1
References:
https://bugzilla.suse.com/1025585https://bugzilla.suse.com/1032074https://bugzilla.suse.com/1037109https://bugzilla.suse.com/1048671https://bugzilla.suse.com/1052352
openSUSE Security Update: Security update for vlc
______________________________________________________________________________
Announcement ID: openSUSE-SU-2017:2597-1
Rating: moderate
References: #1041907 #1057736
Cross-References: CVE-2017-9300
Affected Products:
openSUSE Leap 42.2
______________________________________________________________________________
An update that solves one vulnerability and has one errata
is now available.
Description:
This update for vlc to version 2.2.6 fixes several issues.
This security issue was fixed:
- CVE-2017-9300: Heap corruption allowed remote attackers to cause a
denial of service or possibly have unspecified other impact via a
crafted FLAC file (bsc#1041907).
These non-security issues were fixed:
- Stop depending on libkde4-devel: It's only used to find the install path
for kde4, but configure falls back to the correct default for openSUSE
anyway (boo#1057736).
- Disable vnc access module
For the various other fixes introduced by 2.2.6 please see the changelog.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-1101=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE Leap 42.2 (noarch):
vlc-lang-2.2.6-32.3.1
- openSUSE Leap 42.2 (x86_64):
libvlc5-2.2.6-32.3.1
libvlc5-debuginfo-2.2.6-32.3.1
libvlccore8-2.2.6-32.3.1
libvlccore8-debuginfo-2.2.6-32.3.1
vlc-2.2.6-32.3.1
vlc-codec-gstreamer-2.2.6-32.3.1
vlc-codec-gstreamer-debuginfo-2.2.6-32.3.1
vlc-debuginfo-2.2.6-32.3.1
vlc-debugsource-2.2.6-32.3.1
vlc-devel-2.2.6-32.3.1
vlc-noX-2.2.6-32.3.1
vlc-noX-debuginfo-2.2.6-32.3.1
vlc-qt-2.2.6-32.3.1
vlc-qt-debuginfo-2.2.6-32.3.1
References:
https://www.suse.com/security/cve/CVE-2017-9300.htmlhttps://bugzilla.suse.com/1041907https://bugzilla.suse.com/1057736