SUSE-SU-2019:1806-1

Source
https://www.suse.com/support/update/announcement/2019/suse-su-20191806-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:1806-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2019:1806-1
Related
Published
2019-07-10T09:29:09Z
Modified
2025-05-02T04:08:44.709421Z
Upstream
Summary
Security update for libdlm, libqb
Details

This update for libdlm, libqb fixes the following issues:

libqb to version 1.0.3:

  • CVE-2019-12779: Fixed an insecure treatment of IPC temporary files which could have allowed a local attacker to overwrite privileged system files (bsc#1137835).
  • Enabled use of filesystem sockets for linux (fate#323415).
  • Fixed logging with newer binutils version (bsc#1074327).

libdlm:

  • Explicitly used and linked libstonithd from libpacemaker3 (bsc#1098449).
References

Affected packages

SUSE:Linux Enterprise High Availability Extension 12 SP3 / libdlm

Package

Name
libdlm
Purl
pkg:rpm/suse/libdlm&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.7-3.3.2

Ecosystem specific

{
    "binaries": [
        {
            "libdlm": "4.0.7-3.3.2",
            "libqb0": "1.0.3+20171226.6d62b64-4.3.1",
            "libdlm3": "4.0.7-3.3.2"
        }
    ]
}

SUSE:Linux Enterprise High Availability Extension 12 SP3 / libqb

Package

Name
libqb
Purl
pkg:rpm/suse/libqb&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.3+20171226.6d62b64-4.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libdlm": "4.0.7-3.3.2",
            "libqb0": "1.0.3+20171226.6d62b64-4.3.1",
            "libdlm3": "4.0.7-3.3.2"
        }
    ]
}

SUSE:Linux Enterprise High Availability Extension 12 SP4 / libdlm

Package

Name
libdlm
Purl
pkg:rpm/suse/libdlm&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.7-3.3.2

Ecosystem specific

{
    "binaries": [
        {
            "libdlm": "4.0.7-3.3.2",
            "libqb0": "1.0.3+20171226.6d62b64-4.3.1",
            "libdlm3": "4.0.7-3.3.2"
        }
    ]
}

SUSE:Linux Enterprise High Availability Extension 12 SP4 / libqb

Package

Name
libqb
Purl
pkg:rpm/suse/libqb&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.3+20171226.6d62b64-4.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libdlm": "4.0.7-3.3.2",
            "libqb0": "1.0.3+20171226.6d62b64-4.3.1",
            "libdlm3": "4.0.7-3.3.2"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP4 / libdlm

Package

Name
libdlm
Purl
pkg:rpm/suse/libdlm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.7-3.3.2

Ecosystem specific

{
    "binaries": [
        {
            "libdlm-devel": "4.0.7-3.3.2",
            "libqb-devel": "1.0.3+20171226.6d62b64-4.3.1"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP4 / libqb

Package

Name
libqb
Purl
pkg:rpm/suse/libqb&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.3+20171226.6d62b64-4.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libdlm-devel": "4.0.7-3.3.2",
            "libqb-devel": "1.0.3+20171226.6d62b64-4.3.1"
        }
    ]
}