Security update for SUSE Manager Client Tools
| Announcement ID: | SUSE-SU-202306:15231-1 |
|---|---|
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves one vulnerability, contains one feature and has one security fix can now be installed.
Description:
This update fixes the following issues:
prometheus-apache-exporter:
- CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.
spacecmd:
- Version 4.3.22-1
- Bypass traditional systems check on older SUMA instances (bsc#1208612)
Special Instructions and Notes:
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Manager Client Tools for Ubuntu 22.04 2204
zypper in -t patch suse-ubu224ct-client-tools-202306-15231=1
Package List:
-
SUSE Manager Client Tools for Ubuntu 22.04 2204 (amd64)
- prometheus-apache-exporter-0.11.0-1
-
SUSE Manager Client Tools for Ubuntu 22.04 2204 (all)
- spacecmd-4.3.23-2.24.3