SUSE-SU-2021:0722-1

Source
https://www.suse.com/support/update/announcement/2021/suse-su-20210722-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0722-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2021:0722-1
Related
Published
2021-03-08T15:42:37Z
Modified
2021-03-08T15:42:37Z
Summary
Security update for crmsh
Details

This update for crmsh fixes the following issues:

  • Update to version 4.1.0+git.1614156984.f4f5e146:
    • Fix: hbreport: walk through hbreport process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
    • Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
    • Dev: utils: change default file mod as 644 for str2file function
    • Dev: lock: give more specific error message when raise ClaimLockError
    • Dev: hbreport: Detect if any ocfs2 partitions exist
    • Fix: hbreport: run lsof with specific ocfs2 device(bsc#1180688)
    • Dev: corosync: change the permission of corosync.conf to 644
    • Fix: bootstrap: Use class Watchdog to simplify watchdog config(bsc#1154927, bsc#1178869)
    • Fix: bootstrap: make sure sbd device UUID was the same between nodes(bsc#1178454)
References

Affected packages

SUSE:Linux Enterprise High Availability Extension 12 SP4 / crmsh

Package

Name
crmsh
Purl
pkg:rpm/suse/crmsh&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.0+git.1614156984.f4f5e146-2.56.2

Ecosystem specific

{
    "binaries": [
        {
            "crmsh-scripts": "4.1.0+git.1614156984.f4f5e146-2.56.2",
            "crmsh": "4.1.0+git.1614156984.f4f5e146-2.56.2"
        }
    ]
}

SUSE:Linux Enterprise High Availability Extension 12 SP5 / crmsh

Package

Name
crmsh
Purl
pkg:rpm/suse/crmsh&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.0+git.1614156984.f4f5e146-2.56.2

Ecosystem specific

{
    "binaries": [
        {
            "crmsh-scripts": "4.1.0+git.1614156984.f4f5e146-2.56.2",
            "crmsh": "4.1.0+git.1614156984.f4f5e146-2.56.2"
        }
    ]
}