File _patchinfo of Package patchinfo.9156
<patchinfo incident="9156">
<issue tracker="bnc" id="1104076">VUL-0: CVE-2018-12472: smt: authentication bypass in sibling check</issue>
<issue tracker="bnc" id="1111056">SMT sibling sync issues</issue>
<issue tracker="cve" id="2018-12472"/>
<category>security</category>
<rating>moderate</rating>
<packager>ikapelyukhin</packager>
<description>
SMT was updated to version 3.0.38.
Following security issue was fixed:
- CVE-2018-12472: Harden hostname check during sibling check by forcing double
reverse lookup (bsc#1104076)
Following non security issues were fixed:
- Add migration path check when registration sharing is enabled
- Fix sibling sync errors (bsc#1111056):
- Synchronize all registered products
- Handle duplicate registrations when syncing
- Force resync to the sibling instance in `upgrade` and
`synchronize` API calls
</description>
<summary>Security update for smt</summary>
</patchinfo>