openSUSE Security Update : util-linux (openSUSE-2016-1317)

medium Nessus Plugin ID 94951

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for util-linux fixes a number of bugs and one minor security issue.

The following minor vulnerability was fixed :

- CVE-2016-5011: Infinite loop DoS in libblkid while parsing DOS partition (bsc#988361)

The following bugs were fixed :

- bsc#987176: When mounting a subfolder of a CIFS share, mount -a would show the mount as busy

- bsc#947494: mount -a would fail to recognize btrfs already mounted, address loop re-use in libmount

- bsc#966891: Conflict in meaning of losetup -L. This switch in SLE12 SP1 and SP2 continues to carry the meaning of --logical-blocksize instead of upstream
--nooverlap

- bsc#994399: Package would trigger conflicts with sysvinit-tools

- bsc#983164: mount uid= and gid= would reject valid non UID/GID values

- bsc#978993: cfdisk would mangle some text output

- bsc#982331: libmount: ignore redundant slashes

This update was imported from the SUSE:SLE-12-SP1:Update update project.

Solution

Update the affected util-linux packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=947494

https://bugzilla.opensuse.org/show_bug.cgi?id=966891

https://bugzilla.opensuse.org/show_bug.cgi?id=978993

https://bugzilla.opensuse.org/show_bug.cgi?id=982331

https://bugzilla.opensuse.org/show_bug.cgi?id=983164

https://bugzilla.opensuse.org/show_bug.cgi?id=987176

https://bugzilla.opensuse.org/show_bug.cgi?id=988361

https://bugzilla.opensuse.org/show_bug.cgi?id=994399

Plugin Details

Severity: Medium

ID: 94951

File Name: openSUSE-2016-1317.nasl

Version: 2.5

Type: local

Agent: unix

Published: 11/18/2016

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:util-linux-debugsource, p-cpe:/a:novell:opensuse:util-linux-lang, p-cpe:/a:novell:opensuse:util-linux-systemd, p-cpe:/a:novell:opensuse:libblkid-devel, p-cpe:/a:novell:opensuse:libblkid-devel-32bit, p-cpe:/a:novell:opensuse:libblkid1, p-cpe:/a:novell:opensuse:libblkid1-32bit, p-cpe:/a:novell:opensuse:libblkid1-debuginfo, p-cpe:/a:novell:opensuse:libblkid1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libmount-devel, p-cpe:/a:novell:opensuse:libmount-devel-32bit, p-cpe:/a:novell:opensuse:libmount1, p-cpe:/a:novell:opensuse:libmount1-32bit, p-cpe:/a:novell:opensuse:libmount1-debuginfo, p-cpe:/a:novell:opensuse:libmount1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libsmartcols-devel, p-cpe:/a:novell:opensuse:libsmartcols1, p-cpe:/a:novell:opensuse:libsmartcols1-debuginfo, p-cpe:/a:novell:opensuse:libuuid-devel, p-cpe:/a:novell:opensuse:util-linux-systemd-debuginfo, p-cpe:/a:novell:opensuse:util-linux-systemd-debugsource, p-cpe:/a:novell:opensuse:uuidd, p-cpe:/a:novell:opensuse:uuidd-debuginfo, cpe:/o:novell:opensuse:42.1, p-cpe:/a:novell:opensuse:libuuid-devel-32bit, p-cpe:/a:novell:opensuse:libuuid1, p-cpe:/a:novell:opensuse:libuuid1-32bit, p-cpe:/a:novell:opensuse:libuuid1-debuginfo, p-cpe:/a:novell:opensuse:libuuid1-debuginfo-32bit, p-cpe:/a:novell:opensuse:python-libmount, p-cpe:/a:novell:opensuse:python-libmount-debuginfo, p-cpe:/a:novell:opensuse:python-libmount-debugsource, p-cpe:/a:novell:opensuse:util-linux, p-cpe:/a:novell:opensuse:util-linux-debuginfo

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 11/17/2016

Reference Information

CVE: CVE-2016-5011