openSUSE Recommended Update: Recommended update for libtirpc
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2512-1
Rating: moderate
References: #1072183
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for libtirpc fixes the following issues:
- rpcinfo: send RPC getport call as specified via parameter (bsc#1072183)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-931=1
Package List:
- openSUSE Leap 15.0 (i586 x86_64):
libtirpc-debugsource-1.0.2-lp150.2.3.1
libtirpc-devel-1.0.2-lp150.2.3.1
libtirpc-netconfig-1.0.2-lp150.2.3.1
libtirpc3-1.0.2-lp150.2.3.1
libtirpc3-debuginfo-1.0.2-lp150.2.3.1
- openSUSE Leap 15.0 (x86_64):
libtirpc3-32bit-1.0.2-lp150.2.3.1
libtirpc3-32bit-debuginfo-1.0.2-lp150.2.3.1
References:
https://bugzilla.suse.com/1072183
openSUSE Recommended Update: Recommended update for growpart
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2511-1
Rating: moderate
References: #1097455 #1098681
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has two recommended fixes can now be
installed.
Description:
This update for growpart provides the following fix:
- Support btrfs resize and handle ro setup in rootgrow. (bsc#1097455,
bsc#1098681)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-933=1
Package List:
- openSUSE Leap 15.0 (noarch):
growpart-0.30-lp150.4.3.1
growpart-rootgrow-1.0.0-lp150.4.3.1
References:
https://bugzilla.suse.com/1097455https://bugzilla.suse.com/1098681
openSUSE Security Update: Security update for nextcloud
______________________________________________________________________________
Announcement ID: openSUSE-SU-2018:2510-1
Rating: moderate
References: #1105598
Cross-References: CVE-2018-3780
Affected Products:
SUSE Package Hub for SUSE Linux Enterprise 12
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for nextcloud to version 13.0.5 fixes the following issues:
Security issues fixed:
- CVE-2018-3780: Fixed a missing sanitization of search results for an
autocomplete field that could lead to a stored XSS requiring
user-interaction. The missing sanitization only affected user names,
hence malicious search results could only be crafted by authenticated
users. (boo#1105598)
Other bugs fixed:
- Fix highlighting of the upload drop zone
- Apply ldapUserFilter on members of group
- Make the DELETION of groups match greedy on the groupID
- Add parent index to share table
- Log full exception in cron instead of only the message
- Properly lock the target file on dav upload when not using part files
- LDAP backup server should not be queried when auth fails
- Fix filenames in sharing integration tests
- Lower log level for quota manipulation cases
- Let user set avatar in nextcloud if LDAP provides invalid image data
- Improved logging of smb connection errors
- Allow admin to disable fetching of avatars as well as a specific
attribute
- Allow to disable encryption
- Update message shown when unsharing a file
- Fixed English grammatical error on Settings page.
- Request a valid property for DAV opendir
- Allow updating the token on session regeneration
- Prevent lock values from going negative with memcache backend
- Correctly handle users with numeric user ids
- Correctly parse the subject parameters for link (un)shares of calendars
- Fix "parsing" of email-addresses in comments and chat messages
- Sanitize parameters in createSessionToken() while logging
- Also retry rename operation on InvalidArgumentException
- Improve url detection in comments
- Only bind to ldap if configuration for the first server is set
- Use download manager from PDF.js to download the file
- Fix trying to load removed scripts
- Only pull for new messages if the session is allowed to be kept alive
- Always push object data
- Add prioritization for Talk
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- SUSE Package Hub for SUSE Linux Enterprise 12:
zypper in -t patch openSUSE-2018-936=1
Package List:
- SUSE Package Hub for SUSE Linux Enterprise 12 (noarch):
nextcloud-13.0.5-5.1
References:
https://www.suse.com/security/cve/CVE-2018-3780.htmlhttps://bugzilla.suse.com/1105598
openSUSE Recommended Update: Recommended update for makedumpfile
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2509-1
Rating: moderate
References: #1014136 #1040469 #1068694 #1068925 #1099121
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that has 5 recommended fixes can now be installed.
Description:
This update for makedumpfile fixes the following issues:
- elf_info: Fix file_size if segment is excluded (bsc#1068925).
- Fix the use of Xen physical and machine addresses. (bsc#1014136,
bsc#1068694)
- Revert "Clean up unused KERNEL_IMAGE_SIZE" (bsc#1068925, bsc#1099121).
- Revert "x86_64: kill some unused initialization" (bsc#1068925,
bsc#1099121).
- Revert "x86_64: kill is_vmalloc_addr_x86_64()" (bsc#1068925,
bsc#1099121).
- Revert "x86_64: translate all VA to PA using page table values"
(bsc#1068925, bsc#1099121).
- Revert "x86_64: Calculate page_offset from pt_load" (bsc#1068925,
bsc#1040469, bsc#1099121).
This update was imported from the SUSE:SLE-12-SP3:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-924=1
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
makedumpfile-1.6.1-6.1
makedumpfile-debuginfo-1.6.1-6.1
makedumpfile-debugsource-1.6.1-6.1
References:
https://bugzilla.suse.com/1014136https://bugzilla.suse.com/1040469https://bugzilla.suse.com/1068694https://bugzilla.suse.com/1068925https://bugzilla.suse.com/1099121
openSUSE Recommended Update: Recommended update for rmt-server
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2508-1
Rating: moderate
References: #1094348 #1096967 #1097367 #1097824
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has four recommended fixes can now be
installed.
Description:
This update for rmt-server provides the following fix:
- Use curl instead of wget in rmt-client-setup. (bsc#1094348)
- Improved handling of errors during mirroring. (bsc#1096967)
- Set correct permissions for product.license directory. (bsc#1097367)
- Log version on service startup.
- Bugfix for duplicated migration paths (bsc#1097824)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-923=1
Package List:
- openSUSE Leap 15.0 (x86_64):
rmt-server-1.0.3-lp150.2.6.1
rmt-server-debuginfo-1.0.3-lp150.2.6.1
References:
https://bugzilla.suse.com/1094348https://bugzilla.suse.com/1096967https://bugzilla.suse.com/1097367https://bugzilla.suse.com/1097824
openSUSE Recommended Update: Recommended update for quota
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2507-1
Rating: important
References: #1104898
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for quota fixes the following issues:
- Fix issue with high cpu load if RQUOTAD_PORT is set in
/etc/sysconfig/nfs. (bsc#1104898)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-919=1
Package List:
- openSUSE Leap 15.0 (x86_64):
quota-4.04-lp150.2.3.1
quota-debuginfo-4.04-lp150.2.3.1
quota-debugsource-4.04-lp150.2.3.1
quota-nfs-4.04-lp150.2.3.1
quota-nfs-debuginfo-4.04-lp150.2.3.1
References:
https://bugzilla.suse.com/1104898
openSUSE Optional Update: Optional update for sddm
______________________________________________________________________________
Announcement ID: openSUSE-OU-2018:2506-1
Rating: moderate
References: #1105342
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one optional fix can now be installed.
Description:
This optional update for sddm adds the following functionality:
* Honor PAM's ambient supplemental groups (boo#1105342)
Patch Instructions:
To install this openSUSE Optional Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-921=1
Package List:
- openSUSE Leap 15.0 (x86_64):
sddm-0.17.0-lp150.9.6.1
sddm-branding-openSUSE-0.17.0-lp150.9.6.1
sddm-branding-upstream-0.17.0-lp150.9.6.1
sddm-debuginfo-0.17.0-lp150.9.6.1
sddm-debugsource-0.17.0-lp150.9.6.1
References:
https://bugzilla.suse.com/1105342
openSUSE Recommended Update: Recommended update for spec-cleaner
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2505-1
Rating: moderate
References: #1099674
Affected Products:
openSUSE Leap 42.3
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update brings spec-cleaner to version 1.1.1, including following
fixes and improvements:
* Fix help message not working
* Make libexecdir opt-in rather than opt-out
* Account for LICENCE string not just LICENSE
* Warn about direct qmake/meson usage
* Use https when mentioning bugzilla in header
* Use tuples on some places rather than lists
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-918=1
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-918=1
Package List:
- openSUSE Leap 42.3 (noarch):
spec-cleaner-1.1.1-54.1
spec-cleaner-format_spec_file-1.1.1-54.1
- openSUSE Leap 15.0 (noarch):
spec-cleaner-1.1.1-lp150.2.8.1
spec-cleaner-format_spec_file-1.1.1-lp150.2.8.1
References:
https://bugzilla.suse.com/1099674
openSUSE Recommended Update: Recommended update for Salt
______________________________________________________________________________
Announcement ID: openSUSE-RU-2018:2504-1
Rating: moderate
References: #1057635 #1072599 #1087055 #1087581 #1087891
#1089526 #1092161 #1094055 #1095507 #1096514
#1097174 #1097413 #1098394 #1099323 #1099460
#1099945 #1100142 #1100225 #1100697 #1101812
#1101880 #1102218 #1102265
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has 23 recommended fixes can now be
installed.
Description:
This update for salt fixes the following issues:
- Fix file.blockreplace to avoid throwing IndexError. (bsc#1101812)
- Fix pkg.upgrade reports when dealing with multiversion packages.
(bsc#1102265)
- Fix UnicodeDecodeError using is_binary check. (bsc#1100225)
- Fix corrupt public key with m2crypto python3. (bsc#1099323)
- Prevent payload crash on decoding binary data. (bsc#1100697)
- Accounting for when files in an archive contain non-ascii characters.
(bsc#1099460)
- Handle packages with multiple version properly with zypper. (bsc#1096514)
- Fix file.get_diff regression on 2018.3. (bsc#1098394)
- Provide python version mismatch solutions. (bsc#1072599)
- Add custom SUSE capabilities as Grains. (bsc#1089526)
- Fix file.managed binary file utf8 error. (bsc#1098394)
- Multiversion patch plus upstream fix and patch reordering.
- Add environment variable to know if yum is invoked from Salt.
(bsc#1057635)
- Prevent deprecation warning with salt-ssh. (bsc#1095507)
- Fix for sorting of multi-version packages. (bsc#1097174, bsc#1097413)
- Align SUSE salt-master.service 'LimitNOFILES' limit with upstream Salt.
- Add 'other' attribute to GECOS fields to avoid inconsistencies with chfn.
- Prevent zypper from parsing repo configuration from not .repo files.
(bsc#1094055)
- Collect all versions of installed packages on SUSE and RHEL systems.
(bsc#1089526)
- Fix for [Errno 0] Resolver Error 0 (no error) (bsc#1087581)
- Fix for logging during network interface querying (bsc#1087581)
- Fallback to PyMySQL (bsc#1087891)
- Check dmidecoder executable on each "smbios" call to avoid race
condition (bsc#1101880)
- Fix mine.get not returning data - workaround for #48020 (bsc#1100142)
- Add API log rotation on SUSE package (bsc#1102218)
- Add missing dateutils import (bsc#1099945)
- remove minion/thin/version if exists to force thin regeneration
(bsc#1092161)
- Fix rhel packages requires both net-tools and iproute (bsc#1087055)
- Backport the new libvirt_events engine from upstream
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-920=1
Package List:
- openSUSE Leap 15.0 (x86_64):
python2-salt-2018.3.0-lp150.3.6.1
python3-salt-2018.3.0-lp150.3.6.1
salt-2018.3.0-lp150.3.6.1
salt-api-2018.3.0-lp150.3.6.1
salt-cloud-2018.3.0-lp150.3.6.1
salt-doc-2018.3.0-lp150.3.6.1
salt-master-2018.3.0-lp150.3.6.1
salt-minion-2018.3.0-lp150.3.6.1
salt-proxy-2018.3.0-lp150.3.6.1
salt-ssh-2018.3.0-lp150.3.6.1
salt-syndic-2018.3.0-lp150.3.6.1
- openSUSE Leap 15.0 (noarch):
salt-bash-completion-2018.3.0-lp150.3.6.1
salt-fish-completion-2018.3.0-lp150.3.6.1
salt-zsh-completion-2018.3.0-lp150.3.6.1
References:
https://bugzilla.suse.com/1057635https://bugzilla.suse.com/1072599https://bugzilla.suse.com/1087055https://bugzilla.suse.com/1087581https://bugzilla.suse.com/1087891https://bugzilla.suse.com/1089526https://bugzilla.suse.com/1092161https://bugzilla.suse.com/1094055https://bugzilla.suse.com/1095507https://bugzilla.suse.com/1096514https://bugzilla.suse.com/1097174https://bugzilla.suse.com/1097413https://bugzilla.suse.com/1098394https://bugzilla.suse.com/1099323https://bugzilla.suse.com/1099460https://bugzilla.suse.com/1099945https://bugzilla.suse.com/1100142https://bugzilla.suse.com/1100225https://bugzilla.suse.com/1100697https://bugzilla.suse.com/1101812https://bugzilla.suse.com/1101880https://bugzilla.suse.com/1102218https://bugzilla.suse.com/1102265
openSUSE Security Update: Security update for ImageMagick
______________________________________________________________________________
Announcement ID: openSUSE-SU-2018:2503-1
Rating: moderate
References: #1094741 #1102003 #1102004 #1102005 #1102007
Cross-References: CVE-2018-14434 CVE-2018-14435 CVE-2018-14436
CVE-2018-14437
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that solves four vulnerabilities and has one
errata is now available.
Description:
This update for ImageMagick fixes the following issues:
Security issues fixed:
* CVE-2018-14434: A memory leak for a colormap in WriteMPCImage
incoders/mpc.c was fixed. (bsc#1102003)
* CVE-2018-14435: A memory leak in DecodeImage in coders/pcd.c was fixed.
(bsc#1102007)
* CVE-2018-14436: A memory leak in ReadMIFFImage in coders/miff.c was
fixed. (bsc#1102005)
* CVE-2018-14437: A memory leak in parse8BIM in coders/meta.c was fixed.
(bsc#1102004)
Bug fix:
- bsc#1094741: Fix unexpected result with `convert -compose`.
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-925=1
Package List:
- openSUSE Leap 15.0 (i586 x86_64):
ImageMagick-7.0.7.34-lp150.2.9.1
ImageMagick-debuginfo-7.0.7.34-lp150.2.9.1
ImageMagick-debugsource-7.0.7.34-lp150.2.9.1
ImageMagick-devel-7.0.7.34-lp150.2.9.1
ImageMagick-extra-7.0.7.34-lp150.2.9.1
ImageMagick-extra-debuginfo-7.0.7.34-lp150.2.9.1
libMagick++-7_Q16HDRI4-7.0.7.34-lp150.2.9.1
libMagick++-7_Q16HDRI4-debuginfo-7.0.7.34-lp150.2.9.1
libMagick++-devel-7.0.7.34-lp150.2.9.1
libMagickCore-7_Q16HDRI6-7.0.7.34-lp150.2.9.1
libMagickCore-7_Q16HDRI6-debuginfo-7.0.7.34-lp150.2.9.1
libMagickWand-7_Q16HDRI6-7.0.7.34-lp150.2.9.1
libMagickWand-7_Q16HDRI6-debuginfo-7.0.7.34-lp150.2.9.1
perl-PerlMagick-7.0.7.34-lp150.2.9.1
perl-PerlMagick-debuginfo-7.0.7.34-lp150.2.9.1
- openSUSE Leap 15.0 (x86_64):
ImageMagick-devel-32bit-7.0.7.34-lp150.2.9.1
libMagick++-7_Q16HDRI4-32bit-7.0.7.34-lp150.2.9.1
libMagick++-7_Q16HDRI4-32bit-debuginfo-7.0.7.34-lp150.2.9.1
libMagick++-devel-32bit-7.0.7.34-lp150.2.9.1
libMagickCore-7_Q16HDRI6-32bit-7.0.7.34-lp150.2.9.1
libMagickCore-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-lp150.2.9.1
libMagickWand-7_Q16HDRI6-32bit-7.0.7.34-lp150.2.9.1
libMagickWand-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-lp150.2.9.1
- openSUSE Leap 15.0 (noarch):
ImageMagick-doc-7.0.7.34-lp150.2.9.1
References:
https://www.suse.com/security/cve/CVE-2018-14434.htmlhttps://www.suse.com/security/cve/CVE-2018-14435.htmlhttps://www.suse.com/security/cve/CVE-2018-14436.htmlhttps://www.suse.com/security/cve/CVE-2018-14437.htmlhttps://bugzilla.suse.com/1094741https://bugzilla.suse.com/1102003https://bugzilla.suse.com/1102004https://bugzilla.suse.com/1102005https://bugzilla.suse.com/1102007