Security update for SUSE Manager Server 3.0
This update fixes the following issues: !!!NOTE: For PostgreSQL, schema migrations could take a long time (hours), depending on the number of synced !!! !!!packages and number of rows which requires cleanup. Please refer to the release notes for more information.!!! nutch: - Fix log hadoop into proper directory. (bsc#1061574) osad: - Fixed TypeError for force flag in setup_config that could happen when jabberd restart was needed. (bsc#1064393) pxe-default-image: - Spectre and Meltdown mitigation. (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754, bsc#1068032) spacecmd: - Added custom JSON encoder in order to parse date fields correctly. (bsc#1070372) spacewalk-backend: - Fix restore hostname and ip*addr in templated documents. (bsc#1075044) - Fix directory name in spacewalk-data-fsck. - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-branding: - Fix message about package profile synchronization. (bsc#1073739) - Fix naming of the Tools channel. (bsc#979633) spacewalk-client-tools: - Fix package sources. spacewalk-java: - Fix message about package profile synchronization. (bsc#1073739) - Add VM state as info gathered from VMware. (bsc#1063759) - Improve performance of token checking, when RPMs or metadata are downloaded from minions. (bsc#1061273) - Fix action names and date formatting in system event history. (bsc#1073713) - Fix incorrect 'os-release' report after SP migration. (bsc#1071553) - Fix failed package installation when in RES 32 and 64 bit packages are installed together. (bsc#1071314) - Add user preferences in order to change items-per-page. (bsc#1055296) - Display messages about wrong input more end-user friendly. (bsc#1015956) - Fix content refresh when product keys change. (bsc#1069943) - Allow 'Package List Refresh' when package architecture has changed. (bsc#1065259) - Support Open Enterprise Server 2018. (bsc#1060182) - Do not remove virtual instances for registered systems. (bsc#1063759) - Process right configfile on 'scheduleFileComparisons' API calls. (bsc#1066663) - Fix reported UUIDs for guests instances within a virtual host. (bsc#1063759) - Generate Order Items for OEM subscriptions. (bsc#1045141) - Enable 'Power Management' features on Salt minions. - Fail gracefully when GPG files are requested. (bsc#1065676) - Improve messaging for 'Compare Packages'. (bsc#1065844) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) spacewalk-reports: - More rhnServerNetwork refactoring. (bsc#1063419) spacewalk-search: - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-web: - Add user preferences in order to change items-per-page. (bsc#1055296) susemanager: - Support Open Enterprise Server 2018. (bsc#1060182) - Fixed bootstrap repository path for SLES4SAP version 12 and 12.1. (bsc#1062936) - Fix error message for database upgrade failure. - Check for sufficient diskspace in /var/lib/pgsql. - Notify admin that database backups need reconfiguration after db upgrade. susemanager-docs_en: - Update text and image files: - List Open Enterprise Server 2015, 2015 SP1, 2018 as supported clients. susemanager-schema: - Fix hostname schema upgrade. (bsc#1076622) - Fix duplicate entries in channel listings. - Handle nevra not found case while fixing duplicate evr ids. (bsc#1074508) - Enable 'Power Management' features on Salt minions. - Fix unique index for evr and capability and remove duplicates during migration. (bsc#1058110) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) susemanager-sls: - Python3 compatibility fixes in modules and states. - Fix failing certs state for Tumbleweed. (bsc#970630) - Fix deprecated SLS files to avoid deprecation warnings during highstate. (bsc#1041993) susemanager-sync-data: - Support Open Enterprise Server 2018. (bsc#1060182) - Fix description for HA channel. (bsc#1063588) - Add support for CAASP. (bsc#1052283) - Add IBM DLPAR channels to SLES for SAP SPx ppc64le. (bsc#1068057) - Remove Certification Module 12 from SP2 and SP3. (bsc#1066819) - Add SUSE Manager Server 3.0 and 3.1 channels for mirroring. - Support SLE-RT 12 SP3. (bsc#1063940) - Add SLE12 LTSS as extension to SLES for SAP 12. (bsc#1069615) - Remove OES2018 Debuginfo channels. (bsc#1071367) virtual-host-gatherer: - Add VM state as info gathered from VMware. (bsc#1063759) - Explore the entire tree of nodes from VMware. (bsc#1070597) - Skip safely VMs which have no config attribute on VMware. (bsc#1066923) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: !!!NOTE: For PostgreSQL, schema migrations could take a long time (hours), depending on the number of synced !!! !!!packages and number of rows which requires cleanup. Please refer to the release notes for more information.!!! nutch: - Fix log hadoop into proper directory. (bsc#1061574) osad: - Fixed TypeError for force flag in setup_config that could happen when jabberd restart was needed. (bsc#1064393) pxe-default-image: - Spectre and Meltdown mitigation. (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754, bsc#1068032) spacecmd: - Added custom JSON encoder in order to parse date fields correctly. (bsc#1070372) spacewalk-backend: - Fix restore hostname and ip*addr in templated documents. (bsc#1075044) - Fix directory name in spacewalk-data-fsck. - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-branding: - Fix message about package profile synchronization. (bsc#1073739) - Fix naming of the Tools channel. (bsc#979633) spacewalk-client-tools: - Fix package sources. spacewalk-java: - Fix message about package profile synchronization. (bsc#1073739) - Add VM state as info gathered from VMware. (bsc#1063759) - Improve performance of token checking, when RPMs or metadata are downloaded from minions. (bsc#1061273) - Fix action names and date formatting in system event history. (bsc#1073713) - Fix incorrect 'os-release' report after SP migration. (bsc#1071553) - Fix failed package installation when in RES 32 and 64 bit packages are installed together. (bsc#1071314) - Add user preferences in order to change items-per-page. (bsc#1055296) - Display messages about wrong input more end-user friendly. (bsc#1015956) - Fix content refresh when product keys change. (bsc#1069943) - Allow 'Package List Refresh' when package architecture has changed. (bsc#1065259) - Support Open Enterprise Server 2018. (bsc#1060182) - Do not remove virtual instances for registered systems. (bsc#1063759) - Process right configfile on 'scheduleFileComparisons' API calls. (bsc#1066663) - Fix reported UUIDs for guests instances within a virtual host. (bsc#1063759) - Generate Order Items for OEM subscriptions. (bsc#1045141) - Enable 'Power Management' features on Salt minions. - Fail gracefully when GPG files are requested. (bsc#1065676) - Improve messaging for 'Compare Packages'. (bsc#1065844) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) spacewalk-reports: - More rhnServerNetwork refactoring. (bsc#1063419) spacewalk-search: - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-web: - Add user preferences in order to change items-per-page. (bsc#1055296) susemanager: - Support Open Enterprise Server 2018. (bsc#1060182) - Fixed bootstrap repository path for SLES4SAP version 12 and 12.1. (bsc#1062936) - Fix error message for database upgrade failure. - Check for sufficient diskspace in /var/lib/pgsql. - Notify admin that database backups need reconfiguration after db upgrade. susemanager-docs_en: - Update text and image files: - List Open Enterprise Server 2015, 2015 SP1, 2018 as supported clients. susemanager-schema: - Fix hostname schema upgrade. (bsc#1076622) - Fix duplicate entries in channel listings. - Handle nevra not found case while fixing duplicate evr ids. (bsc#1074508) - Enable 'Power Management' features on Salt minions. - Fix unique index for evr and capability and remove duplicates during migration. (bsc#1058110) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) susemanager-sls: - Python3 compatibility fixes in modules and states. - Fix failing certs state for Tumbleweed. (bsc#970630) - Fix deprecated SLS files to avoid deprecation warnings during highstate. (bsc#1041993) susemanager-sync-data: - Support Open Enterprise Server 2018. (bsc#1060182) - Fix description for HA channel. (bsc#1063588) - Add support for CAASP. (bsc#1052283) - Add IBM DLPAR channels to SLES for SAP SPx ppc64le. (bsc#1068057) - Remove Certification Module 12 from SP2 and SP3. (bsc#1066819) - Add SUSE Manager Server 3.0 and 3.1 channels for mirroring. - Support SLE-RT 12 SP3. (bsc#1063940) - Add SLE12 LTSS as extension to SLES for SAP 12. (bsc#1069615) - Remove OES2018 Debuginfo channels. (bsc#1071367) virtual-host-gatherer: - Add VM state as info gathered from VMware. (bsc#1063759) - Explore the entire tree of nodes from VMware. (bsc#1070597) - Skip safely VMs which have no config attribute on VMware. (bsc#1066923) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1015956
- https://bugzilla.suse.com/1041993
- https://bugzilla.suse.com/1045141
- https://bugzilla.suse.com/1052283
- https://bugzilla.suse.com/1055296
- https://bugzilla.suse.com/1058110
- https://bugzilla.suse.com/1060182
- https://bugzilla.suse.com/1061273
- https://bugzilla.suse.com/1061574
- https://bugzilla.suse.com/1062936
- https://bugzilla.suse.com/1063419
- https://bugzilla.suse.com/1063588
- https://bugzilla.suse.com/1063759
- https://bugzilla.suse.com/1063891
- https://bugzilla.suse.com/1063940
- https://bugzilla.suse.com/1064393
- https://bugzilla.suse.com/1065259
- https://bugzilla.suse.com/1065676
- https://bugzilla.suse.com/1065844
- https://bugzilla.suse.com/1066404
- https://bugzilla.suse.com/1066663
- https://bugzilla.suse.com/1066819
- https://bugzilla.suse.com/1066923
- https://bugzilla.suse.com/1068032
- https://bugzilla.suse.com/1068057
- https://bugzilla.suse.com/1069615
- https://bugzilla.suse.com/1069943
- https://bugzilla.suse.com/1070372
- https://bugzilla.suse.com/1070597
- https://bugzilla.suse.com/1071314
- https://bugzilla.suse.com/1071367
- https://bugzilla.suse.com/1071553
- https://bugzilla.suse.com/1073713
- https://bugzilla.suse.com/1073739
- https://bugzilla.suse.com/1074508
- https://bugzilla.suse.com/1075044
- https://bugzilla.suse.com/1076622
- https://bugzilla.suse.com/970630
- https://bugzilla.suse.com/979633
- https://www.suse.com/security/cve/CVE-2017-5715
- https://www.suse.com/security/cve/CVE-2017-5753
- https://www.suse.com/security/cve/CVE-2017-5754
- https://www.suse.com/support/update/announcement/2018/suse-su-20180285-1/