FlawAtlas
Search the atlas
SUSE-SU-2018:0285-1 Not scored

Security update for SUSE Manager Server 3.0

This update fixes the following issues: !!!NOTE: For PostgreSQL, schema migrations could take a long time (hours), depending on the number of synced !!! !!!packages and number of rows which requires cleanup. Please refer to the release notes for more information.!!! nutch: - Fix log hadoop into proper directory. (bsc#1061574) osad: - Fixed TypeError for force flag in setup_config that could happen when jabberd restart was needed. (bsc#1064393) pxe-default-image: - Spectre and Meltdown mitigation. (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754, bsc#1068032) spacecmd: - Added custom JSON encoder in order to parse date fields correctly. (bsc#1070372) spacewalk-backend: - Fix restore hostname and ip*addr in templated documents. (bsc#1075044) - Fix directory name in spacewalk-data-fsck. - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-branding: - Fix message about package profile synchronization. (bsc#1073739) - Fix naming of the Tools channel. (bsc#979633) spacewalk-client-tools: - Fix package sources. spacewalk-java: - Fix message about package profile synchronization. (bsc#1073739) - Add VM state as info gathered from VMware. (bsc#1063759) - Improve performance of token checking, when RPMs or metadata are downloaded from minions. (bsc#1061273) - Fix action names and date formatting in system event history. (bsc#1073713) - Fix incorrect 'os-release' report after SP migration. (bsc#1071553) - Fix failed package installation when in RES 32 and 64 bit packages are installed together. (bsc#1071314) - Add user preferences in order to change items-per-page. (bsc#1055296) - Display messages about wrong input more end-user friendly. (bsc#1015956) - Fix content refresh when product keys change. (bsc#1069943) - Allow 'Package List Refresh' when package architecture has changed. (bsc#1065259) - Support Open Enterprise Server 2018. (bsc#1060182) - Do not remove virtual instances for registered systems. (bsc#1063759) - Process right configfile on 'scheduleFileComparisons' API calls. (bsc#1066663) - Fix reported UUIDs for guests instances within a virtual host. (bsc#1063759) - Generate Order Items for OEM subscriptions. (bsc#1045141) - Enable 'Power Management' features on Salt minions. - Fail gracefully when GPG files are requested. (bsc#1065676) - Improve messaging for 'Compare Packages'. (bsc#1065844) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) spacewalk-reports: - More rhnServerNetwork refactoring. (bsc#1063419) spacewalk-search: - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-web: - Add user preferences in order to change items-per-page. (bsc#1055296) susemanager: - Support Open Enterprise Server 2018. (bsc#1060182) - Fixed bootstrap repository path for SLES4SAP version 12 and 12.1. (bsc#1062936) - Fix error message for database upgrade failure. - Check for sufficient diskspace in /var/lib/pgsql. - Notify admin that database backups need reconfiguration after db upgrade. susemanager-docs_en: - Update text and image files: - List Open Enterprise Server 2015, 2015 SP1, 2018 as supported clients. susemanager-schema: - Fix hostname schema upgrade. (bsc#1076622) - Fix duplicate entries in channel listings. - Handle nevra not found case while fixing duplicate evr ids. (bsc#1074508) - Enable 'Power Management' features on Salt minions. - Fix unique index for evr and capability and remove duplicates during migration. (bsc#1058110) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) susemanager-sls: - Python3 compatibility fixes in modules and states. - Fix failing certs state for Tumbleweed. (bsc#970630) - Fix deprecated SLS files to avoid deprecation warnings during highstate. (bsc#1041993) susemanager-sync-data: - Support Open Enterprise Server 2018. (bsc#1060182) - Fix description for HA channel. (bsc#1063588) - Add support for CAASP. (bsc#1052283) - Add IBM DLPAR channels to SLES for SAP SPx ppc64le. (bsc#1068057) - Remove Certification Module 12 from SP2 and SP3. (bsc#1066819) - Add SUSE Manager Server 3.0 and 3.1 channels for mirroring. - Support SLE-RT 12 SP3. (bsc#1063940) - Add SLE12 LTSS as extension to SLES for SAP 12. (bsc#1069615) - Remove OES2018 Debuginfo channels. (bsc#1071367) virtual-host-gatherer: - Add VM state as info gathered from VMware. (bsc#1063759) - Explore the entire tree of nodes from VMware. (bsc#1070597) - Skip safely VMs which have no config attribute on VMware. (bsc#1066923) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start

Exploit probability Not scored
Published January 30, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Manager Server 3.0 nutch
SUSE:Manager Server 3.0 osad
SUSE:Manager Server 3.0 pxe-default-image
SUSE:Manager Server 3.0 spacecmd
SUSE:Manager Server 3.0 spacewalk-backend
SUSE:Manager Server 3.0 spacewalk-branding
SUSE:Manager Server 3.0 spacewalk-client-tools
SUSE:Manager Server 3.0 spacewalk-java
SUSE:Manager Server 3.0 spacewalk-reports
SUSE:Manager Server 3.0 spacewalk-search
SUSE:Manager Server 3.0 spacewalk-web
SUSE:Manager Server 3.0 susemanager
SUSE:Manager Server 3.0 susemanager-docs_en
SUSE:Manager Server 3.0 susemanager-schema
SUSE:Manager Server 3.0 susemanager-sls
SUSE:Manager Server 3.0 susemanager-sync-data
SUSE:Manager Server 3.0 virtual-host-gatherer

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:0285-1

This update fixes the following issues: !!!NOTE: For PostgreSQL, schema migrations could take a long time (hours), depending on the number of synced !!! !!!packages and number of rows which requires cleanup. Please refer to the release notes for more information.!!! nutch: - Fix log hadoop into proper directory. (bsc#1061574) osad: - Fixed TypeError for force flag in setup_config that could happen when jabberd restart was needed. (bsc#1064393) pxe-default-image: - Spectre and Meltdown mitigation. (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754, bsc#1068032) spacecmd: - Added custom JSON encoder in order to parse date fields correctly. (bsc#1070372) spacewalk-backend: - Fix restore hostname and ip*addr in templated documents. (bsc#1075044) - Fix directory name in spacewalk-data-fsck. - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-branding: - Fix message about package profile synchronization. (bsc#1073739) - Fix naming of the Tools channel. (bsc#979633) spacewalk-client-tools: - Fix package sources. spacewalk-java: - Fix message about package profile synchronization. (bsc#1073739) - Add VM state as info gathered from VMware. (bsc#1063759) - Improve performance of token checking, when RPMs or metadata are downloaded from minions. (bsc#1061273) - Fix action names and date formatting in system event history. (bsc#1073713) - Fix incorrect 'os-release' report after SP migration. (bsc#1071553) - Fix failed package installation when in RES 32 and 64 bit packages are installed together. (bsc#1071314) - Add user preferences in order to change items-per-page. (bsc#1055296) - Display messages about wrong input more end-user friendly. (bsc#1015956) - Fix content refresh when product keys change. (bsc#1069943) - Allow 'Package List Refresh' when package architecture has changed. (bsc#1065259) - Support Open Enterprise Server 2018. (bsc#1060182) - Do not remove virtual instances for registered systems. (bsc#1063759) - Process right configfile on 'scheduleFileComparisons' API calls. (bsc#1066663) - Fix reported UUIDs for guests instances within a virtual host. (bsc#1063759) - Generate Order Items for OEM subscriptions. (bsc#1045141) - Enable 'Power Management' features on Salt minions. - Fail gracefully when GPG files are requested. (bsc#1065676) - Improve messaging for 'Compare Packages'. (bsc#1065844) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) spacewalk-reports: - More rhnServerNetwork refactoring. (bsc#1063419) spacewalk-search: - RhnServerNetwork refactoring. (bsc#1063419) spacewalk-web: - Add user preferences in order to change items-per-page. (bsc#1055296) susemanager: - Support Open Enterprise Server 2018. (bsc#1060182) - Fixed bootstrap repository path for SLES4SAP version 12 and 12.1. (bsc#1062936) - Fix error message for database upgrade failure. - Check for sufficient diskspace in /var/lib/pgsql. - Notify admin that database backups need reconfiguration after db upgrade. susemanager-docs_en: - Update text and image files: - List Open Enterprise Server 2015, 2015 SP1, 2018 as supported clients. susemanager-schema: - Fix hostname schema upgrade. (bsc#1076622) - Fix duplicate entries in channel listings. - Handle nevra not found case while fixing duplicate evr ids. (bsc#1074508) - Enable 'Power Management' features on Salt minions. - Fix unique index for evr and capability and remove duplicates during migration. (bsc#1058110) - RhnServerNetwork refactoring. (bsc#1063419) - Add Adelaide timezone to selectable timezones. (bsc#1063891) susemanager-sls: - Python3 compatibility fixes in modules and states. - Fix failing certs state for Tumbleweed. (bsc#970630) - Fix deprecated SLS files to avoid deprecation warnings during highstate. (bsc#1041993) susemanager-sync-data: - Support Open Enterprise Server 2018. (bsc#1060182) - Fix description for HA channel. (bsc#1063588) - Add support for CAASP. (bsc#1052283) - Add IBM DLPAR channels to SLES for SAP SPx ppc64le. (bsc#1068057) - Remove Certification Module 12 from SP2 and SP3. (bsc#1066819) - Add SUSE Manager Server 3.0 and 3.1 channels for mirroring. - Support SLE-RT 12 SP3. (bsc#1063940) - Add SLE12 LTSS as extension to SLES for SAP 12. (bsc#1069615) - Remove OES2018 Debuginfo channels. (bsc#1071367) virtual-host-gatherer: - Add VM state as info gathered from VMware. (bsc#1063759) - Explore the entire tree of nodes from VMware. (bsc#1070597) - Skip safely VMs which have no config attribute on VMware. (bsc#1066923) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start

View original source

05 / REFERENCES

Further evidence