Security update for couchdb

Announcement ID: SUSE-SU-2018:2765-1
Rating: moderate
References:
Cross-References:
CVSS scores:
  • CVE-2018-8007 ( SUSE ): 8.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • CVE-2018-8007 ( NVD ): 7.2 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products:
  • SUSE Linux Enterprise High Performance Computing 12 SP3
  • SUSE Linux Enterprise Server 12 SP3
  • SUSE OpenStack Cloud Crowbar 8

An update that solves one vulnerability can now be installed.

Description:

This update for couchdb fixes the following security issues:

  • CVE-2018-8007: Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it was possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API (bsc#1100973)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE OpenStack Cloud Crowbar 8
    zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2018-1930=1

Package List:

  • SUSE OpenStack Cloud Crowbar 8 (x86_64)
    • couchdb-debuginfo-1.7.2-3.3.1
    • couchdb-debugsource-1.7.2-3.3.1
    • couchdb-1.7.2-3.3.1

References: