File _patchinfo of Package patchinfo.10141
<patchinfo incident="10141">
<issue tracker="bnc" id="1125666">Invalid exit codes in supportconfig</issue>
<issue tracker="bnc" id="1099498">hostinfo reports two kernel version installation dates</issue>
<issue tracker="bnc" id="1115245">Supportconfig collecting rotated messages and warn logs</issue>
<issue tracker="bnc" id="1118462">VUL-0: CVE-2018-19639: supportutils: Code execution if run with -v</issue>
<issue tracker="bnc" id="1118463">VUL-1: CVE-2018-19640: supportutils: Users can kill arbitrary processes</issue>
<issue tracker="bnc" id="1118460">VUL-1: CVE-2018-19638: supportutils: User can overwrite arbitrary log files in support tar</issue>
<issue tracker="bnc" id="1125623">SUSE separation in supportconfig</issue>
<issue tracker="bnc" id="1117776">VUL-1: CVE-2018-19637: supportutils: Static temporary filename allows overwriting of files</issue>
<issue tracker="bnc" id="1117751">VUL-0: EMBARGOED: CVE-2018-19636: supportutils: Local root exploit via inclusion of attacker controlled shell script</issue>
<issue tracker="bnc" id="1054979">hostinfo throws wrong information on network cards</issue>
<issue tracker="cve" id="2018-19640"/>
<issue tracker="cve" id="2018-19638"/>
<issue tracker="cve" id="2018-19636"/>
<issue tracker="cve" id="2018-19637"/>
<issue tracker="cve" id="2018-19639"/>
<category>security</category>
<rating>important</rating>
<packager>jrecord</packager>
<description>This update for hostinfo, supportutils fixes the following issues:
Security issues fixed for supportutils:
- CVE-2018-19640: Fixed an issue where users could kill arbitrary processes (bsc#1118463).
- CVE-2018-19638: Fixed an issue where users could overwrite arbitrary log files (bsc#1118460).
- CVE-2018-19639: Fixed a code execution if run with -v (bsc#1118462).
- CVE-2018-19637: Fixed an issue where static temporary filename could allow overwriting of files (bsc#1117776).
- CVE-2018-19636: Fixed a local root exploit via inclusion of attacker controlled shell script (bsc#1117751).
Other issues fixed for supportutils:
- Fixed invalid exit code commands (bsc#1125666)
- SUSE separation in supportconfig (bsc#1125623)
- Clarified supportconfig(8) -x option (bsc#1115245)
- supportconfig: 3.0.127
- btrfs filesystem usage
- List products.d
- Dump lsof errors
- Added ha commands for corosync
- Dumped find errors in ib_info
Issues fixed in hostinfo:
- Removed extra kernel install dates (bsc#1099498)
- Resolved network bond issue (bsc#1054979)
This update was imported from the SUSE:SLE-12:Update update project.</description>
<summary>Security update for hostinfo, supportutils</summary>
</patchinfo>