openSUSE Security Update : the_silver_searcher (openSUSE-2017-850)

medium Nessus Plugin ID 102052

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for the_silver_searcher to version 2.0.0 fixes a minor security issue and includes various improvements.

New and updated functionality :

- New and updated support for various file types

- Performance improvements, including faster substring search

- Add --print-all-files options to print all files searched

- Add support for inverting ignore rules (e.g. !blah.txt)

- Add zsh completion function

The following functionality has changed :

- No longer read from .agignore, .ignore is used

The following potential security issue was fixed :

- Heap buffer overflow when searching an absolute path (boo#1050057)

The following bug fixes are included :

- Fix context line printing when reading from a pipe

- Ignore local-domain socket just like named pipes

- Fix --word-regexp not applying to alternates

Solution

Update the affected the_silver_searcher packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1050057

Plugin Details

Severity: Medium

ID: 102052

File Name: openSUSE-2017-850.nasl

Version: 3.3

Type: local

Agent: unix

Published: 7/31/2017

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:the_silver_searcher, p-cpe:/a:novell:opensuse:the_silver_searcher-debuginfo, p-cpe:/a:novell:opensuse:the_silver_searcher-debugsource, cpe:/o:novell:opensuse:42.2, cpe:/o:novell:opensuse:42.3

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 7/27/2017