Security update for SUSE Studio
This update provides SUSE Studio 1.3.10, including Amazon's EC2 support for SUSE Linux Enterprise 12 appliances. Additionally, the update includes fixes for the following issues: * #904372 - Arbitrary file existence disclosure in sprockets gem (CVE-2014-7819) * #904375 - Arbitrary file existence disclosure in Action Pack gem (CVE-2014-7818) * #918203 - Arbitrary file existence disclosure in Studio Onsite (CVE-2014-7829) * #852794 - SLES 11-SP3 templates fail to build x86_64 EC2 images * #914765 - Change of appliance name is not displayed in appliance's change log * #887893 - Change log not accessible via API * #918239 - Failure to create new appliances after upgrade to Studio Onsite 1.3.9 * #918395 - Remove 32bit as target for building EC2 appliances * #912512 - Studio doesn't allow duplicated repositories * #880078 - Studio packages contain files that get modified (by Studio) after installation. * #919037 - Can't open appliance on Gallery: undefined restructure_unsupportable_packages method. Security Issues: * CVE-2014-7819 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7819> * CVE-2014-7818 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7818> * CVE-2014-7829 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7829>
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update provides SUSE Studio 1.3.10, including Amazon's EC2 support for SUSE Linux Enterprise 12 appliances. Additionally, the update includes fixes for the following issues: * #904372 - Arbitrary file existence disclosure in sprockets gem (CVE-2014-7819) * #904375 - Arbitrary file existence disclosure in Action Pack gem (CVE-2014-7818) * #918203 - Arbitrary file existence disclosure in Studio Onsite (CVE-2014-7829) * #852794 - SLES 11-SP3 templates fail to build x86_64 EC2 images * #914765 - Change of appliance name is not displayed in appliance's change log * #887893 - Change log not accessible via API * #918239 - Failure to create new appliances after upgrade to Studio Onsite 1.3.9 * #918395 - Remove 32bit as target for building EC2 appliances * #912512 - Studio doesn't allow duplicated repositories * #880078 - Studio packages contain files that get modified (by Studio) after installation. * #919037 - Can't open appliance on Gallery: undefined restructure_unsupportable_packages method. Security Issues: * CVE-2014-7819 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7819> * CVE-2014-7818 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7818> * CVE-2014-7829 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7829>
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/852794
- https://bugzilla.suse.com/876313
- https://bugzilla.suse.com/880078
- https://bugzilla.suse.com/887893
- https://bugzilla.suse.com/904372
- https://bugzilla.suse.com/904375
- https://bugzilla.suse.com/912512
- https://bugzilla.suse.com/914765
- https://bugzilla.suse.com/918203
- https://bugzilla.suse.com/918239
- https://bugzilla.suse.com/918395
- https://bugzilla.suse.com/919037
- https://www.suse.com/security/cve/CVE-2014-7818
- https://www.suse.com/security/cve/CVE-2014-7819
- https://www.suse.com/security/cve/CVE-2014-7829
- https://www.suse.com/support/update/announcement/2015/suse-su-20150863-1/