Security update for SUSE Manager Client Tools
This update fixes the following issues: cobbler: - Fix parsing cobbler dictionary options with values containing '=', e.g. kernel params containing '=' (bsc#1176978) mgr-daemon: - Update translation strings salt: - Properly validate eauth credentials and tokens on SSH calls made by Salt API (bsc#1178319, bsc#1178362, bsc#1178361, CVE-2020-25592, CVE-2020-17490, CVE-2020-16846) spacecmd: - Python3 fixes for errata in spacecmd (bsc#1169664) - Added support for i18n of user-facing strings - Python3 fix for sorted usage (bsc#1167907) spacewalk-client-tools: - Remove RH references in Python/Ruby localization and use the product name instead
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: cobbler: - Fix parsing cobbler dictionary options with values containing '=', e.g. kernel params containing '=' (bsc#1176978) mgr-daemon: - Update translation strings salt: - Properly validate eauth credentials and tokens on SSH calls made by Salt API (bsc#1178319, bsc#1178362, bsc#1178361, CVE-2020-25592, CVE-2020-17490, CVE-2020-16846) spacecmd: - Python3 fixes for errata in spacecmd (bsc#1169664) - Added support for i18n of user-facing strings - Python3 fix for sorted usage (bsc#1167907) spacewalk-client-tools: - Remove RH references in Python/Ruby localization and use the product name instead
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1167907
- https://bugzilla.suse.com/1169664
- https://bugzilla.suse.com/1176978
- https://bugzilla.suse.com/1178319
- https://bugzilla.suse.com/1178361
- https://bugzilla.suse.com/1178362
- https://www.suse.com/security/cve/CVE-2020-16846
- https://www.suse.com/security/cve/CVE-2020-17490
- https://www.suse.com/security/cve/CVE-2020-25592
- https://www.suse.com/support/update/announcement/2020/suse-su-202014538-1/