Security update for libstorage
SUSE Patch
security@suse.de
SUSE Security Team
openSUSE-SU-2016:2264-1
Final
1
1
2016-09-08T09:31:17Z
current
2016-09-08T09:31:17Z
2016-09-08T09:31:17Z
cve-database/bin/generate-cvrf.pl
2017-02-24T01:00:00Z
Security update for libstorage
This update for libstorage fixes the following issues:
- Use stdin, not tmp files for passwords (bsc#986971, CVE-2016-5746)
This update was imported from the SUSE:SLE-12-SP1:Update update project.
The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)
https://lists.opensuse.org/opensuse-updates/2016-09/msg00032.html
E-Mail link for openSUSE-SU-2016:2264-1
https://www.suse.com/support/security/rating/
SUSE Security Ratings
openSUSE Leap 42.1
libstorage-2.25.35.1-6.1
libstorage-devel-2.25.35.1-6.1
libstorage-python-2.25.35.1-6.1
libstorage-ruby-2.25.35.1-6.1
libstorage-testsuite-2.25.35.1-6.1
libstorage6-2.25.35.1-6.1
yast2-storage-3.1.71-4.1
yast2-storage-devel-3.1.71-4.1
libstorage-2.25.35.1-6.1 as a component of openSUSE Leap 42.1
libstorage-devel-2.25.35.1-6.1 as a component of openSUSE Leap 42.1
libstorage-python-2.25.35.1-6.1 as a component of openSUSE Leap 42.1
libstorage-ruby-2.25.35.1-6.1 as a component of openSUSE Leap 42.1
libstorage-testsuite-2.25.35.1-6.1 as a component of openSUSE Leap 42.1
libstorage6-2.25.35.1-6.1 as a component of openSUSE Leap 42.1
yast2-storage-3.1.71-4.1 as a component of openSUSE Leap 42.1
yast2-storage-devel-3.1.71-4.1 as a component of openSUSE Leap 42.1
libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-XXXXXX/pwdf.
CVE-2016-5746
openSUSE Leap 42.1:libstorage-2.25.35.1-6.1
openSUSE Leap 42.1:libstorage-devel-2.25.35.1-6.1
openSUSE Leap 42.1:libstorage-python-2.25.35.1-6.1
openSUSE Leap 42.1:libstorage-ruby-2.25.35.1-6.1
openSUSE Leap 42.1:libstorage-testsuite-2.25.35.1-6.1
openSUSE Leap 42.1:libstorage6-2.25.35.1-6.1
openSUSE Leap 42.1:yast2-storage-3.1.71-4.1
openSUSE Leap 42.1:yast2-storage-devel-3.1.71-4.1
moderate
4.7
AV:L/AC:H/Au:N/C:C/I:P/A:N
Please Install the update.
https://lists.opensuse.org/opensuse-updates/2016-09/msg00032.html
https://www.suse.com/security/cve/CVE-2016-5746.html
CVE-2016-5746
https://bugzilla.suse.com/984245
SUSE Bug 984245
https://bugzilla.suse.com/986971
SUSE Bug 986971