SUSE-SU-2018:2898-2

Source
https://www.suse.com/support/update/announcement/2018/suse-su-20182898-2/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-2.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2018:2898-2
Upstream
  • CVE-2018-12470
  • CVE-2018-12471
  • CVE-2018-12472
Related
  • CVE-2018-12470
  • CVE-2018-12471
  • CVE-2018-12472
Published
2018-10-18T12:49:39Z
Modified
2026-02-04T03:19:54Z
Summary
Security update for smt, yast2-smt
Details

This update for yast2-smt to 3.0.14 and smt to 3.0.37 fixes the following issues:

These security issues were fixed in SMT:

  • CVE-2018-12471: Xml External Entity processing in the RegistrationSharing modules allowed to read arbitrary file read (bsc#1103809).
  • CVE-2018-12470: SQL injection in RegistrationSharing module allows remote attackers to run arbitrary SQL statements (bsc#1103810).
  • CVE-2018-12472: Authentication bypass in sibling check facilitated further attacks on SMT (bsc#1104076).

SUSE would like to thank Jake Miller for reporting these issues to us.

These non-security issues were fixed in SMT:

  • Fix cron jobs randomization (bsc#1097560)
  • Fix duplicate migration paths (bsc#1097824)

This non-security issue was fixed in yast2-smt:

  • Remove cron job rescheduling (bsc#1097560)
  • Added missing translation marks (bsc#1037811)
  • Explicitly mention 'Organization Credentials' (fate#321759)
  • Rearrange the SMT set-up dialog (bsc#977043)
  • Make the Filter button default (bsc#1006984)
  • Prevent exiting the repo selection dialog via hitting Enter in the repository filter (bsc#1006984)
  • report when error occurs during repo mirroring (bsc#1006989)
  • Use TextEntry-based filter for repos (fate#319777)
References

Affected packages

SUSE:Linux Enterprise Server 12 SP2-BCL / smt

Package

Name
smt
Purl
pkg:rpm/suse/smt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.37-52.23.6

Ecosystem specific

{
    "binaries": [
        {
            "res-signingkeys": "3.0.37-52.23.6",
            "smt": "3.0.37-52.23.6",
            "smt-support": "3.0.37-52.23.6"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:2898-2.json"