Security update for texlive-filesystem

Announcement ID: SUSE-SU-2020:1580-2
Rating: moderate
References:
Cross-References:
CVSS scores:
  • CVE-2020-8016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2020-8017 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected Products:
  • Desktop Applications Module 15-SP2
  • SUSE Linux Enterprise Desktop 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise Real Time 15 SP2
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP2 Business Critical Linux 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Manager Proxy 4.1
  • SUSE Manager Retail Branch Server 4.1
  • SUSE Manager Server 4.1

An update that solves two vulnerabilities can now be installed.

Description:

This update for texlive-filesystem fixes the following issues:

Security issues fixed:

  • CVE-2020-8016: Fixed a race condition in the spec file (bsc#1159740).
  • CVE-2020-8017: Fixed a race condition on a cron job (bsc#1158910).

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • Desktop Applications Module 15-SP2
    zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-1580=1

Package List:

  • Desktop Applications Module 15-SP2 (noarch)
    • texlive-collection-latex-2017.135.svn41614-9.12.1
    • texlive-filesystem-2017.135-9.12.1
    • texlive-scheme-small-2017.135.svn41825-9.12.1
    • texlive-collection-formatsextra-2017.135.svn44177-9.12.1
    • texlive-collection-langfrench-2017.135.svn40375-9.12.1
    • texlive-collection-langgreek-2017.135.svn44192-9.12.1
    • texlive-extratools-2017.135-9.12.1
    • texlive-scheme-tetex-2017.135.svn44187-9.12.1
    • texlive-collection-luatex-2017.135.svn44500-9.12.1
    • texlive-collection-metapost-2017.135.svn44297-9.12.1
    • texlive-collection-context-2017.135.svn42330-9.12.1
    • texlive-collection-pstricks-2017.135.svn44460-9.12.1
    • texlive-collection-fontsextra-2017.135.svn43356-9.12.1
    • texlive-collection-langczechslovak-2017.135.svn32550-9.12.1
    • texlive-collection-fontutils-2017.135.svn37105-9.12.1
    • texlive-collection-fontsrecommended-2017.135.svn35830-9.12.1
    • texlive-collection-langcyrillic-2017.135.svn44401-9.12.1
    • texlive-collection-langenglish-2017.135.svn43650-9.12.1
    • texlive-collection-plaingeneric-2017.135.svn44177-9.12.1
    • texlive-collection-bibtexextra-2017.135.svn44385-9.12.1
    • texlive-scheme-basic-2017.135.svn25923-9.12.1
    • texlive-collection-langjapanese-2017.135.svn44554-9.12.1
    • texlive-collection-langportuguese-2017.135.svn30962-9.12.1
    • texlive-collection-langcjk-2017.135.svn43009-9.12.1
    • texlive-collection-publishers-2017.135.svn44485-9.12.1
    • texlive-scheme-minimal-2017.135.svn13822-9.12.1
    • texlive-collection-pictures-2017.135.svn44395-9.12.1
    • texlive-collection-langgerman-2017.135.svn42045-9.12.1
    • texlive-collection-basic-2017.135.svn41616-9.12.1
    • texlive-collection-langkorean-2017.135.svn42106-9.12.1
    • texlive-collection-langarabic-2017.135.svn44496-9.12.1
    • texlive-collection-langpolish-2017.135.svn44371-9.12.1
    • texlive-collection-langspanish-2017.135.svn40587-9.12.1
    • texlive-collection-binextra-2017.135.svn44515-9.12.1
    • texlive-devel-2017.135-9.12.1
    • texlive-scheme-infraonly-2017.135.svn41515-9.12.1
    • texlive-collection-latexrecommended-2017.135.svn44177-9.12.1
    • texlive-collection-humanities-2017.135.svn42268-9.12.1
    • texlive-scheme-gust-2017.135.svn44177-9.12.1
    • texlive-collection-mathscience-2017.135.svn44396-9.12.1
    • texlive-collection-xetex-2017.135.svn43059-9.12.1
    • texlive-collection-langitalian-2017.135.svn30372-9.12.1
    • texlive-scheme-context-2017.135.svn35799-9.12.1
    • texlive-collection-latexextra-2017.135.svn44544-9.12.1
    • texlive-collection-langeuropean-2017.135.svn44414-9.12.1
    • texlive-scheme-medium-2017.135.svn44177-9.12.1
    • texlive-collection-games-2017.135.svn42992-9.12.1
    • texlive-collection-langchinese-2017.135.svn42675-9.12.1
    • texlive-collection-langother-2017.135.svn44414-9.12.1
    • texlive-scheme-full-2017.135.svn44177-9.12.1
    • texlive-collection-music-2017.135.svn40561-9.12.1

References: