openSUSE Recommended Update: Recommended update for polkit-default-privs
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2522-1
Rating: moderate
References: #1100328
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for polkit-default-privs fixes the following issues:
- Contains whitelisting for new libvirt polkit action (bsc#1100328)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-927=1
Package List:
- openSUSE Leap 15.0 (noarch):
polkit-default-privs-13.2-lp150.8.3.1
References:
https://bugzilla.suse.com/1100328
openSUSE Security Update: Security update for nextcloud
______________________________________________________________________________
Announcement ID: openSUSE-SU-2018:2521-1
Rating: moderate
References: #1105598
Cross-References: CVE-2018-3780
Affected Products:
openSUSE Leap 42.3
openSUSE Leap 15.0
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for nextcloud to version 13.0.5 fixes the following issues:
Security issues fixed:
- CVE-2018-3780: Fixed a missing sanitization of search results for an
autocomplete field that could lead to a stored XSS requiring
user-interaction. The missing sanitization only affected user names,
hence malicious search results could only be crafted by authenticated
users. (boo#1105598)
Other bugs fixed:
- Fix highlighting of the upload drop zone
- Apply ldapUserFilter on members of group
- Make the DELETION of groups match greedy on the groupID
- Add parent index to share table
- Log full exception in cron instead of only the message
- Properly lock the target file on dav upload when not using part files
- LDAP backup server should not be queried when auth fails
- Fix filenames in sharing integration tests
- Lower log level for quota manipulation cases
- Let user set avatar in nextcloud if LDAP provides invalid image data
- Improved logging of smb connection errors
- Allow admin to disable fetching of avatars as well as a specific
attribute
- Allow to disable encryption
- Update message shown when unsharing a file
- Fixed English grammatical error on Settings page.
- Request a valid property for DAV opendir
- Allow updating the token on session regeneration
- Prevent lock values from going negative with memcache backend
- Correctly handle users with numeric user ids
- Correctly parse the subject parameters for link (un)shares of calendars
- Fix "parsing" of email-addresses in comments and chat messages
- Sanitize parameters in createSessionToken() while logging
- Also retry rename operation on InvalidArgumentException
- Improve url detection in comments
- Only bind to ldap if configuration for the first server is set
- Use download manager from PDF.js to download the file
- Fix trying to load removed scripts
- Only pull for new messages if the session is allowed to be kept alive
- Always push object data
- Add prioritization for Talk
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-936=1
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-936=1
Package List:
- openSUSE Leap 42.3 (noarch):
nextcloud-13.0.5-12.1
- openSUSE Leap 15.0 (noarch):
nextcloud-13.0.5-lp150.2.6.1
References:
https://www.suse.com/security/cve/CVE-2018-3780.htmlhttps://bugzilla.suse.com/1105598
openSUSE Recommended Update: Recommended update for growpart
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2520-1
Rating: moderate
References: #1082318 #1097455 #1098681
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that has three recommended fixes can now be
installed.
Description:
This update for growpart provides the following fix:
- Support btrfs resize and handle ro setup in rootgrow. (bsc#1097455,
bsc#1098681)
- Use %license instead of %doc in the package. (bsc#1082318)
This update was imported from the SUSE:SLE-12:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-932=1
Package List:
- openSUSE Leap 42.3 (noarch):
growpart-0.30-11.6.1
growpart-rootgrow-1.0.0-11.6.1
References:
https://bugzilla.suse.com/1082318https://bugzilla.suse.com/1097455https://bugzilla.suse.com/1098681
openSUSE Recommended Update: Recommended update for ca-certificates-mozilla
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2519-1
Rating: moderate
References: #1104780
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for ca-certificates-mozilla fixes the following issues:
Updated to the 2.26 state of the Mozilla NSS Certificate store.
(bsc#1104780)
- removed server auth rights from following CAs:
- Certplus Root CA G1
- Certplus Root CA G2
- OpenTrust Root CA G1
- OpenTrust Root CA G2
- OpenTrust Root CA G3
- removed CA
- ComSign CA
- new CA added:
- GlobalSign
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-935=1
Package List:
- openSUSE Leap 15.0 (noarch):
ca-certificates-mozilla-2.26-lp150.3.6.1
References:
https://bugzilla.suse.com/1104780
openSUSE Recommended Update: Recommended update for dracut
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2518-1
Rating: moderate
References: #1048551 #1065058 #1091099 #1094603
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has four recommended fixes can now be
installed.
Description:
This update for dracut fixes the following issues:
- Fix an issue with static network setups (bsc#1091099)
- Fix cat: write error: Broken pipe error (bsc#1094603)
- Pickup multipath files in /etc/multipath/conf.d (bsc#1048551)
- Load all keymaps for a given locale (bsc#1065058)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-934=1
Package List:
- openSUSE Leap 15.0 (i586 x86_64):
dracut-044.1-lp150.14.3.1
dracut-debuginfo-044.1-lp150.14.3.1
dracut-debugsource-044.1-lp150.14.3.1
dracut-fips-044.1-lp150.14.3.1
dracut-ima-044.1-lp150.14.3.1
dracut-tools-044.1-lp150.14.3.1
References:
https://bugzilla.suse.com/1048551https://bugzilla.suse.com/1065058https://bugzilla.suse.com/1091099https://bugzilla.suse.com/1094603
openSUSE Recommended Update: Recommended update for perf
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2515-1
Rating: moderate
References: #1075525
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for perf fixes the following issues:
- Bugfix: PMU events were not listed because pvr code was missing for
POWER9 (bsc#1075525)
This update was imported from the SUSE:SLE-12-SP3:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-926=1
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
perf-4.4.143-50.1
perf-debuginfo-4.4.143-50.1
perf-debugsource-4.4.143-50.1
References:
https://bugzilla.suse.com/1075525
openSUSE Recommended Update: Recommended update for calibre
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2513-1
Rating: moderate
References: #1105930
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for calibre fixes the following issues:
- Add support for new Kobo (4.10.11586) and Kindle firmware versions
(boo#1105930)
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-929=1
Package List:
- openSUSE Leap 15.0 (x86_64):
calibre-3.27.1-lp150.3.9.1
calibre-debuginfo-3.27.1-lp150.3.9.1
calibre-debugsource-3.27.1-lp150.3.9.1
References:
https://bugzilla.suse.com/1105930