SUSE-SU-2017:2935-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20172935-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2935-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:2935-1
Upstream
  • CVE-2017-15638
Related
  • CVE-2017-15638
Published
2017-11-06T16:19:18Z
Modified
2026-02-04T03:05:54Z
Summary
Security update for SuSEfirewall2
Details

This update for SuSEfirewall2 fixes the following issues:

  • CVE-2017-15638: Fixed security issue with too open implicit portmapper rules (bsc#1064127): A source net restriction for rpc services was not taken into account for the implicitly added rules for port 111, making the portmap service accessible to everyone in the affected zone when the 'rpc' matching was used.
References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP3
SuSEfirewall2

Package

Name
SuSEfirewall2
Purl
pkg:rpm/suse/SuSEfirewall2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.312.333-3.10.1

Ecosystem specific

{
    "binaries": [
        {
            "SuSEfirewall2": "3.6.312.333-3.10.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2935-1.json"
SUSE:Linux Enterprise Server 12 SP3
SuSEfirewall2

Package

Name
SuSEfirewall2
Purl
pkg:rpm/suse/SuSEfirewall2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.312.333-3.10.1

Ecosystem specific

{
    "binaries": [
        {
            "SuSEfirewall2": "3.6.312.333-3.10.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2935-1.json"
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
SuSEfirewall2

Package

Name
SuSEfirewall2
Purl
pkg:rpm/suse/SuSEfirewall2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.312.333-3.10.1

Ecosystem specific

{
    "binaries": [
        {
            "SuSEfirewall2": "3.6.312.333-3.10.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2935-1.json"