openSUSE Security Update : util-linux (openSUSE-2017-306)

medium Nessus Plugin ID 97565

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for util-linux fixes the following issues :

This security issue was fixed :

- CVE-2017-2616: In su with PAM support it was possible for local users to send SIGKILL to selected other processes with root privileges (bsc#1023041).

This non-security issues were fixed :

- lscpu: Implement WSL detection and work around crash (bsc#1019332)

- fstrim: De-duplicate btrfs sub-volumes for 'fstrim -a' and bind mounts (bsc#1020077)

- Fix regressions in safe loop re-use patch set for libmount (bsc#1012504)

- Disable ro checks for mtab (bsc#1012632)

- Ensure that the option 'users,exec,dev,suid' work as expected on NFS mounts (bsc#1008965)

- Fix empty slave detection to prevent 100% CPU load in some cases (bsc#1020985)

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Solution

Update the affected util-linux packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1008965

https://bugzilla.opensuse.org/show_bug.cgi?id=1012504

https://bugzilla.opensuse.org/show_bug.cgi?id=1012632

https://bugzilla.opensuse.org/show_bug.cgi?id=1019332

https://bugzilla.opensuse.org/show_bug.cgi?id=1020077

https://bugzilla.opensuse.org/show_bug.cgi?id=1020985

https://bugzilla.opensuse.org/show_bug.cgi?id=1023041

Plugin Details

Severity: Medium

ID: 97565

File Name: openSUSE-2017-306.nasl

Version: 3.4

Type: local

Agent: unix

Published: 3/7/2017

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:libblkid-devel, p-cpe:/a:novell:opensuse:libblkid-devel-32bit, p-cpe:/a:novell:opensuse:libblkid-devel-static, p-cpe:/a:novell:opensuse:libblkid1, p-cpe:/a:novell:opensuse:libblkid1-32bit, p-cpe:/a:novell:opensuse:libblkid1-debuginfo, p-cpe:/a:novell:opensuse:libblkid1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libfdisk-devel, p-cpe:/a:novell:opensuse:libfdisk-devel-static, p-cpe:/a:novell:opensuse:libfdisk1, p-cpe:/a:novell:opensuse:libfdisk1-debuginfo, p-cpe:/a:novell:opensuse:libmount-devel, p-cpe:/a:novell:opensuse:libmount-devel-32bit, p-cpe:/a:novell:opensuse:libmount-devel-static, p-cpe:/a:novell:opensuse:libmount1, p-cpe:/a:novell:opensuse:libmount1-32bit, p-cpe:/a:novell:opensuse:libmount1-debuginfo, p-cpe:/a:novell:opensuse:libmount1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libsmartcols-devel, p-cpe:/a:novell:opensuse:libsmartcols-devel-static, p-cpe:/a:novell:opensuse:libsmartcols1, p-cpe:/a:novell:opensuse:libsmartcols1-debuginfo, p-cpe:/a:novell:opensuse:libuuid-devel, p-cpe:/a:novell:opensuse:libuuid-devel-32bit, p-cpe:/a:novell:opensuse:libuuid-devel-static, p-cpe:/a:novell:opensuse:libuuid1, p-cpe:/a:novell:opensuse:libuuid1-32bit, p-cpe:/a:novell:opensuse:libuuid1-debuginfo, p-cpe:/a:novell:opensuse:libuuid1-debuginfo-32bit, p-cpe:/a:novell:opensuse:python-libmount, p-cpe:/a:novell:opensuse:python-libmount-debuginfo, p-cpe:/a:novell:opensuse:python-libmount-debugsource, p-cpe:/a:novell:opensuse:util-linux, p-cpe:/a:novell:opensuse:util-linux-debuginfo, p-cpe:/a:novell:opensuse:util-linux-debugsource, p-cpe:/a:novell:opensuse:util-linux-lang, p-cpe:/a:novell:opensuse:util-linux-systemd, p-cpe:/a:novell:opensuse:util-linux-systemd-debuginfo, p-cpe:/a:novell:opensuse:util-linux-systemd-debugsource, p-cpe:/a:novell:opensuse:uuidd, p-cpe:/a:novell:opensuse:uuidd-debuginfo, cpe:/o:novell:opensuse:42.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 3/2/2017

Reference Information

CVE: CVE-2017-2616