openSUSE Security Update : resource-agents (openSUSE-2020-585)

high Nessus Plugin ID 136308

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for resource-agents fixes the following issues :

- Fixed multiple vulnerabilities related to unsafe tempfile usage. (bsc#1146690 bsc#1146691 bsc#1146692 bsc#1146766 bsc#1146776 bsc#1146784 bsc#1146785 bsc#1146787)

- Fixed issues where the ocfmon user was created with a default password (bsc#1021689, bsc#1146687).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Solution

Update the affected resource-agents packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1021689

https://bugzilla.opensuse.org/show_bug.cgi?id=1146687

https://bugzilla.opensuse.org/show_bug.cgi?id=1146690

https://bugzilla.opensuse.org/show_bug.cgi?id=1146691

https://bugzilla.opensuse.org/show_bug.cgi?id=1146692

https://bugzilla.opensuse.org/show_bug.cgi?id=1146766

https://bugzilla.opensuse.org/show_bug.cgi?id=1146776

https://bugzilla.opensuse.org/show_bug.cgi?id=1146784

https://bugzilla.opensuse.org/show_bug.cgi?id=1146785

https://bugzilla.opensuse.org/show_bug.cgi?id=1146787

Plugin Details

Severity: High

ID: 136308

File Name: openSUSE-2020-585.nasl

Version: 1.1

Type: local

Agent: unix

Published: 5/4/2020

Updated: 5/4/2020

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Nessus

Vulnerability Information

CPE: cpe:/o:novell:opensuse:15.1, p-cpe:/a:novell:opensuse:resource-agents, p-cpe:/a:novell:opensuse:resource-agents-debuginfo, p-cpe:/a:novell:opensuse:resource-agents-debugsource, p-cpe:/a:novell:opensuse:ldirectord, p-cpe:/a:novell:opensuse:monitoring-plugins-metadata

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 5/1/2020

Vulnerability Publication Date: 5/1/2020