openSUSE Security Update : util-linux (openSUSE-2016-1446)

Medium Nessus Plugin ID 95752

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for util-linux fixes the following issues :

- Consider redundant slashes when comparing paths (bsc#982331, util-linux-libmount-ignore-redundant-slashes.patch, affects backport of util-linux-libmount-cifs-is_mounted.patch).

- Use upstream compatibility patches for
--show-pt-geometry with obsolescence and deprecation warning (bsc#990531)

- Replace cifs mount detection patch with upstream one that covers all cases (bsc#987176).

- Reuse existing loop device to prevent possible data corruption when multiple -o loop are used to mount a single file (bsc#947494)

- Safe loop re-use in libmount, mount and losetup (bsc#947494)

- UPSTREAM DIVERGENCE!!! losetup -L continues to use SLE12 SP1 and SP2 specific meaning

--logical-blocksize instead of upstream --nooverlap (bsc#966891).

- Make release-dependent conflict with old sysvinit-tools SLE specific, as it is required only for SLE 11 upgrade, and breaks openSUSE staging builds (bsc#994399).

- Extended partition loop in MBR partition table leads to DoS (bsc#988361, CVE-2016-5011)

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Solution

Update the affected util-linux packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=947494

https://bugzilla.opensuse.org/show_bug.cgi?id=966891

https://bugzilla.opensuse.org/show_bug.cgi?id=982331

https://bugzilla.opensuse.org/show_bug.cgi?id=987176

https://bugzilla.opensuse.org/show_bug.cgi?id=988361

https://bugzilla.opensuse.org/show_bug.cgi?id=990531

https://bugzilla.opensuse.org/show_bug.cgi?id=994399

Plugin Details

Severity: Medium

ID: 95752

File Name: openSUSE-2016-1446.nasl

Version: Revision: 3.3

Type: local

Agent: unix

Published: 2016/12/13

Updated: 2018/01/26

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 4.7

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

CVSS v3.0

Base Score: 4.3

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:libblkid-devel, p-cpe:/a:novell:opensuse:libblkid-devel-32bit, p-cpe:/a:novell:opensuse:libblkid-devel-static, p-cpe:/a:novell:opensuse:libblkid1, p-cpe:/a:novell:opensuse:libblkid1-32bit, p-cpe:/a:novell:opensuse:libblkid1-debuginfo, p-cpe:/a:novell:opensuse:libblkid1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libfdisk-devel, p-cpe:/a:novell:opensuse:libfdisk-devel-static, p-cpe:/a:novell:opensuse:libfdisk1, p-cpe:/a:novell:opensuse:libfdisk1-debuginfo, p-cpe:/a:novell:opensuse:libmount-devel, p-cpe:/a:novell:opensuse:libmount-devel-32bit, p-cpe:/a:novell:opensuse:libmount-devel-static, p-cpe:/a:novell:opensuse:libmount1, p-cpe:/a:novell:opensuse:libmount1-32bit, p-cpe:/a:novell:opensuse:libmount1-debuginfo, p-cpe:/a:novell:opensuse:libmount1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libsmartcols-devel, p-cpe:/a:novell:opensuse:libsmartcols-devel-static, p-cpe:/a:novell:opensuse:libsmartcols1, p-cpe:/a:novell:opensuse:libsmartcols1-debuginfo, p-cpe:/a:novell:opensuse:libuuid-devel, p-cpe:/a:novell:opensuse:libuuid-devel-32bit, p-cpe:/a:novell:opensuse:libuuid-devel-static, p-cpe:/a:novell:opensuse:libuuid1, p-cpe:/a:novell:opensuse:libuuid1-32bit, p-cpe:/a:novell:opensuse:libuuid1-debuginfo, p-cpe:/a:novell:opensuse:libuuid1-debuginfo-32bit, p-cpe:/a:novell:opensuse:python-libmount, p-cpe:/a:novell:opensuse:python-libmount-debuginfo, p-cpe:/a:novell:opensuse:python-libmount-debugsource, p-cpe:/a:novell:opensuse:util-linux, p-cpe:/a:novell:opensuse:util-linux-debuginfo, p-cpe:/a:novell:opensuse:util-linux-debugsource, p-cpe:/a:novell:opensuse:util-linux-lang, p-cpe:/a:novell:opensuse:util-linux-systemd, p-cpe:/a:novell:opensuse:util-linux-systemd-debuginfo, p-cpe:/a:novell:opensuse:util-linux-systemd-debugsource, p-cpe:/a:novell:opensuse:uuidd, p-cpe:/a:novell:opensuse:uuidd-debuginfo, cpe:/o:novell:opensuse:42.2

Patch Publication Date: 2016/12/12

Reference Information

CVE: CVE-2016-5011