Security update for conntrack-tools

SUSE Security Update: Security update for conntrack-tools
Announcement ID: SUSE-SU-2015:1545-1
Rating: moderate
References: #942149 #944339
Affected Products:
  • SUSE OpenStack Cloud Compute 5
  • SUSE Linux Enterprise Software Development Kit 12
  • SUSE Linux Enterprise High Availability 12

  • An update that solves one vulnerability and has one errata is now available.

    Description:


    Fix a possible crash if conntrackd sees DCCP, SCTP and ICMPv6 traffic and
    the corresponding kernel modules that track this traffic are not
    available. (bsc#942149, CVE-2015-6496)

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE OpenStack Cloud Compute 5:
      zypper in -t patch SUSE-SLE12-CLOUD-5-2015-527=1
    • SUSE Linux Enterprise Software Development Kit 12:
      zypper in -t patch SUSE-SLE-SDK-12-2015-527=1
    • SUSE Linux Enterprise High Availability 12:
      zypper in -t patch SUSE-SLE-HA-12-2015-527=1

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE OpenStack Cloud Compute 5 (x86_64):
      • conntrack-tools-1.4.2-5.2
      • conntrack-tools-debuginfo-1.4.2-5.2
      • conntrack-tools-debugsource-1.4.2-5.2
      • libnetfilter_cthelper-debugsource-1.0.0-7.1
      • libnetfilter_cthelper0-1.0.0-7.1
      • libnetfilter_cthelper0-debuginfo-1.0.0-7.1
      • libnetfilter_cttimeout-debugsource-1.0.0-9.1
      • libnetfilter_cttimeout1-1.0.0-9.1
      • libnetfilter_cttimeout1-debuginfo-1.0.0-9.1
    • SUSE Linux Enterprise Software Development Kit 12 (ppc64le s390x x86_64):
      • libnetfilter_cthelper-debugsource-1.0.0-7.1
      • libnetfilter_cthelper-devel-1.0.0-7.1
      • libnetfilter_cthelper0-1.0.0-7.1
      • libnetfilter_cthelper0-debuginfo-1.0.0-7.1
      • libnetfilter_cttimeout-debugsource-1.0.0-9.1
      • libnetfilter_cttimeout-devel-1.0.0-9.1
      • libnetfilter_cttimeout1-1.0.0-9.1
      • libnetfilter_cttimeout1-debuginfo-1.0.0-9.1
    • SUSE Linux Enterprise High Availability 12 (s390x x86_64):
      • conntrack-tools-1.4.2-5.2
      • conntrack-tools-debuginfo-1.4.2-5.2
      • conntrack-tools-debugsource-1.4.2-5.2
      • libnetfilter_cthelper-debugsource-1.0.0-7.1
      • libnetfilter_cthelper0-1.0.0-7.1
      • libnetfilter_cthelper0-debuginfo-1.0.0-7.1
      • libnetfilter_cttimeout-debugsource-1.0.0-9.1
      • libnetfilter_cttimeout1-1.0.0-9.1
      • libnetfilter_cttimeout1-debuginfo-1.0.0-9.1

    References: