SUSE-SU-2018:2898-1

Source
https://www.suse.com/support/update/announcement/2018/suse-su-20182898-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2018:2898-1
Upstream
CVE (3)
  • CVE-2018-12470
  • CVE-2018-12471
  • CVE-2018-12472
Related
Published
2018-09-27T12:47:15Z
Modified
2026-02-04T03:15:44Z
Summary
Security update for smt, yast2-smt
Details

This update for yast2-smt to 3.0.14 and smt to 3.0.37 fixes the following issues:

These security issues were fixed in SMT:

  • CVE-2018-12471: Xml External Entity processing in the RegistrationSharing modules allowed to read arbitrary file read (bsc#1103809).
  • CVE-2018-12470: SQL injection in RegistrationSharing module allows remote attackers to run arbitrary SQL statements (bsc#1103810).
  • CVE-2018-12472: Authentication bypass in sibling check facilitated further attacks on SMT (bsc#1104076).

SUSE would like to thank Jake Miller for reporting these issues to us.

These non-security issues were fixed in SMT:

  • Fix cron jobs randomization (bsc#1097560)
  • Fix duplicate migration paths (bsc#1097824)

This non-security issue was fixed in yast2-smt:

  • Remove cron job rescheduling (bsc#1097560)
  • Added missing translation marks (bsc#1037811)
  • Explicitly mention 'Organization Credentials' (fate#321759)
  • Rearrange the SMT set-up dialog (bsc#977043)
  • Make the Filter button default (bsc#1006984)
  • Prevent exiting the repo selection dialog via hitting Enter in the repository filter (bsc#1006984)
  • report when error occurs during repo mirroring (bsc#1006989)
  • Use TextEntry-based filter for repos (fate#319777)
References

Affected packages

SUSE:Enterprise Storage 4
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Enterprise%20Storage%204

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:Linux Enterprise Module for Public Cloud 12
perl-File-Touch

Package

Name
perl-File-Touch
Purl
pkg:rpm/suse/perl-File-Touch&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.11-3.2.2

Ecosystem specific

{
    "binaries":  [
        {
            "perl-File-Touch":  "0.11-3.2.2",
            "smt-ha":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "perl-File-Touch":  "0.11-3.2.2",
            "smt-ha":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:Linux Enterprise Server 12 SP1-LTSS
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6",
            "yast2-smt":  "3.0.14-10.6.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
yast2-smt

Package

Name
yast2-smt
Purl
pkg:rpm/suse/yast2-smt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.14-10.6.2

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6",
            "yast2-smt":  "3.0.14-10.6.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:Linux Enterprise Server 12 SP2-LTSS
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:Linux Enterprise Server 12 SP3
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:Linux Enterprise Server for SAP Applications 12 SP1
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6",
            "yast2-smt":  "3.0.14-10.6.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
yast2-smt

Package

Name
yast2-smt
Purl
pkg:rpm/suse/yast2-smt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.14-10.6.2

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6",
            "yast2-smt":  "3.0.14-10.6.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"
SUSE:OpenStack Cloud 7
smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries":  [
        {
            "res-signingkeys":  "3.0.37-52.23.6",
            "smt":  "3.0.37-52.23.6",
            "smt-support":  "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-1.json"