Re: URGENT!!! OpenSuse Security Patches

Originally Posted by
nrickert
Run Yast online update.
That should apply all available security updates.
However, your tests might still show a problem, if the tests are based on the version number rather than on testing for the security flaw. It is common practice in many distros, to back-patch the security fix to the installed version. So the fixed version may still have a version number that the tester does not like.
Hi
Correct, once upto date the OP needs to check the changelogs for the CVE numbers, for example (this is on Leap 42.1);
Code:
rpm -qa --changelog|grep 2015-0204
* CVE-2015-0204 (bnc#912014)
- added openssl-CVE-2015-0204.patch
* CVE-2015-0204 (bnc#912014)
- added openssl-CVE-2015-0204.patch
* CVE-2015-0204 (bnc#912014)
- added openssl-CVE-2015-0204.patch
rpm -qa --changelog|grep 2014-1591
* MFSA 2014-86/CVE-2014-1591 (bmo#1069762)
rpm -qa --changelog|grep 2014-9447
- CVE-2014-9447: elfutils: Directory traversal vulnerability (bnc#911662)
- CVE-2014-9447: elfutils: Directory traversal vulnerability (bnc#911662)
- CVE-2014-9447: elfutils: Directory traversal vulnerability (bnc#911662)
- CVE-2014-9447: elfutils: Directory traversal vulnerability (bnc#911662)
Cheers Malcolm °¿° SUSE Knowledge Partner (Linux Counter #276890)
SUSE SLE, openSUSE Leap/Tumbleweed (x86_64) | GNOME DE
If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below... Thanks!
Bookmarks