openSUSE Recommended Update: Recommended update for ipmitool
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:0818-1
Rating: moderate
References: #1179133 #1185162 #1185684
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has three recommended fixes can now be
installed.
Description:
This update for ipmitool fixes the following issues:
- Deprecated the use of /var/run. Moved to /run now (bsc#1185162)
- Fixed a delay when trying to identify the appropriate cipher suite
(bsc#1179133)
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-818=1
Package List:
- openSUSE Leap 15.2 (noarch):
ipmitool-bmc-snmp-proxy-1.8.18+git20200204.7ccea28-lp152.2.3.1
- openSUSE Leap 15.2 (x86_64):
ipmitool-1.8.18+git20200204.7ccea28-lp152.2.3.1
ipmitool-debuginfo-1.8.18+git20200204.7ccea28-lp152.2.3.1
ipmitool-debugsource-1.8.18+git20200204.7ccea28-lp152.2.3.1
References:
https://bugzilla.suse.com/1179133https://bugzilla.suse.com/1185162https://bugzilla.suse.com/1185684
openSUSE Recommended Update: Recommended update for radvd
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:0816-1
Rating: moderate
References: #1185066
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for radvd fixes the following issues:
- replace '/var/run' with '/run' in '/usr/lib/tmpfiles.d/radvd.conf'
(bsc#1185066)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-816=1
Package List:
- openSUSE Leap 15.2 (i586 x86_64):
radvd-2.17-lp152.6.3.1
radvd-debuginfo-2.17-lp152.6.3.1
radvd-debugsource-2.17-lp152.6.3.1
References:
https://bugzilla.suse.com/1185066
openSUSE Recommended Update: Recommended update for yast2-migration
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:0815-1
Rating: moderate
References: #1185808
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for yast2-migration fixes the following issues:
- Show the new base product license in online migration. (bsc#1185808)
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-815=1
Package List:
- openSUSE Leap 15.2 (noarch):
yast2-migration-4.2.5-lp152.2.3.1
References:
https://bugzilla.suse.com/1185808
openSUSE Recommended Update: Recommended update for msmtp
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:0814-1
Rating: moderate
References: #1186323
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for msmtp fixes the following issues:
Backported OAUTH2 support to msmtp (boo#1186323).
* Add support for XOAUTH2 authentication.
* Fix XOAUTH2 when libgsasl is used
* passwordeval: allow longer password
* passwordeval: read only the first line
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-814=1
Package List:
- openSUSE Leap 15.2 (x86_64):
msmtp-1.8.10-lp152.2.3.1
msmtp-debuginfo-1.8.10-lp152.2.3.1
msmtp-debugsource-1.8.10-lp152.2.3.1
msmtp-doc-1.8.10-lp152.2.3.1
msmtp-mta-1.8.10-lp152.2.3.1
References:
https://bugzilla.suse.com/1186323
openSUSE Recommended Update: Recommended update for grpc
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:0817-1
Rating: moderate
References: #1184116
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for grpc fixes the following issues:
- Build and install .cmake files [boo#1184116]
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-817=1
Package List:
- openSUSE Leap 15.2 (x86_64):
grpc-debuginfo-1.25.0-lp152.2.3.1
grpc-debugsource-1.25.0-lp152.2.3.1
grpc-devel-1.25.0-lp152.2.3.1
grpc-devel-debuginfo-1.25.0-lp152.2.3.1
libgrpc++1-1.25.0-lp152.2.3.1
libgrpc++1-debuginfo-1.25.0-lp152.2.3.1
libgrpc8-1.25.0-lp152.2.3.1
libgrpc8-debuginfo-1.25.0-lp152.2.3.1
python2-grpcio-1.25.0-lp152.2.3.1
python2-grpcio-debuginfo-1.25.0-lp152.2.3.1
python3-grpcio-1.25.0-lp152.2.3.1
python3-grpcio-debuginfo-1.25.0-lp152.2.3.1
- openSUSE Leap 15.2 (noarch):
grpc-source-1.25.0-lp152.2.3.1
References:
https://bugzilla.suse.com/1184116
openSUSE Security Update: Security update for libxls
______________________________________________________________________________
Announcement ID: openSUSE-SU-2021:0812-1
Rating: moderate
References: #1179532
Cross-References: CVE-2020-27819
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for libxls fixes the following issues:
libxsl was updated to release 1.6.2:
* Fix NULL pointer dereferences in the xls2csv tool [boo#1179532]
[CVE-2020-27819]
Update to release 1.6.1
* Enabled decoding of non-Unicode character sets in older (BIFF5) XLS
files.
* Improved string conversion performance in newer files.
update to 1.5.3:
* Allow truncated XLS files
* Fix long-standing "extra column" bug #73
* Support for RSTRING records (rich-text cells in older BIFF5 files)
tidyverse/readxl#611
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-812=1
Package List:
- openSUSE Leap 15.2 (x86_64):
libxls-debuginfo-1.6.2-lp152.2.3.1
libxls-debugsource-1.6.2-lp152.2.3.1
libxls-devel-1.6.2-lp152.2.3.1
libxls-tools-1.6.2-lp152.2.3.1
libxls-tools-debuginfo-1.6.2-lp152.2.3.1
libxlsreader8-1.6.2-lp152.2.3.1
libxlsreader8-debuginfo-1.6.2-lp152.2.3.1
References:
https://www.suse.com/security/cve/CVE-2020-27819.htmlhttps://bugzilla.suse.com/1179532
openSUSE Recommended Update: Recommended update for rawtherapee
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:0811-1
Rating: moderate
References: #1186455
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for rawtherapee fixes the following issues:
- Fix segfault on exit, add patch fix-segfault-on-exit.patch boo#1186455
- Adding -fno-tree-loop-vectorize because GCC10 causes a weird bug:
https://github.com/Beep6581/RawTherapee/issues/5749
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-811=1
Package List:
- openSUSE Leap 15.2 (x86_64):
rawtherapee-5.8-lp152.2.3.1
rawtherapee-debuginfo-5.8-lp152.2.3.1
rawtherapee-debugsource-5.8-lp152.2.3.1
References:
https://bugzilla.suse.com/1186455
openSUSE Security Update: Security update for singularity
______________________________________________________________________________
Announcement ID: openSUSE-SU-2021:0810-1
Rating: moderate
References: #1184147
Cross-References: CVE-2021-29136
CVSS scores:
CVE-2021-29136 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVE-2021-29136 (SUSE): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected Products:
openSUSE Backports SLE-15-SP2
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for singularity fixes the following issues:
singularity was updated to version 3.7.3:
- Fix for CVE-2021-29136: A dependency used to extract docker/OCI image
layers can be tricked into modifying host files by creating a malicious
layer that has a symlink with the name "." (or "/"), when running as
root.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP2:
zypper in -t patch openSUSE-2021-810=1
Package List:
- openSUSE Backports SLE-15-SP2 (aarch64 s390x x86_64):
singularity-3.7.3-bp152.2.19.3
References:
https://www.suse.com/security/cve/CVE-2021-29136.htmlhttps://bugzilla.suse.com/1184147
openSUSE Recommended Update: Recommended update for motif
______________________________________________________________________________
Announcement ID: openSUSE-RU-2021:0809-1
Rating: moderate
References: #1184184
Affected Products:
openSUSE Leap 15.2
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for motif fixes the following issues:
- Add patches to prevent the third party application crashing.
(bsc#1184184)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-809=1
Package List:
- openSUSE Leap 15.2 (i586 x86_64):
libMrm4-2.3.4-lp152.4.3.1
libMrm4-debuginfo-2.3.4-lp152.4.3.1
libUil4-2.3.4-lp152.4.3.1
libUil4-debuginfo-2.3.4-lp152.4.3.1
libXm4-2.3.4-lp152.4.3.1
libXm4-debuginfo-2.3.4-lp152.4.3.1
motif-2.3.4-lp152.4.3.1
motif-debuginfo-2.3.4-lp152.4.3.1
motif-debugsource-2.3.4-lp152.4.3.1
motif-devel-2.3.4-lp152.4.3.1
motif-devel-debuginfo-2.3.4-lp152.4.3.1
- openSUSE Leap 15.2 (x86_64):
libMrm4-32bit-2.3.4-lp152.4.3.1
libMrm4-32bit-debuginfo-2.3.4-lp152.4.3.1
libUil4-32bit-2.3.4-lp152.4.3.1
libUil4-32bit-debuginfo-2.3.4-lp152.4.3.1
libXm4-32bit-2.3.4-lp152.4.3.1
libXm4-32bit-debuginfo-2.3.4-lp152.4.3.1
motif-devel-32bit-2.3.4-lp152.4.3.1
motif-devel-32bit-debuginfo-2.3.4-lp152.4.3.1
References:
https://bugzilla.suse.com/1184184