{"affected":[{"ecosystem_specific":{"binaries":[{"SuSEfirewall2":"3.6.312.333-3.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP3","name":"SuSEfirewall2","purl":"pkg:rpm/suse/SuSEfirewall2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.6.312.333-3.10.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"SuSEfirewall2":"3.6.312.333-3.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"SuSEfirewall2","purl":"pkg:rpm/suse/SuSEfirewall2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.6.312.333-3.10.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"SuSEfirewall2":"3.6.312.333-3.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"SuSEfirewall2","purl":"pkg:rpm/suse/SuSEfirewall2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.6.312.333-3.10.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for SuSEfirewall2 fixes the following issues:\n\n- CVE-2017-15638: Fixed security issue with too open implicit portmapper rules\n  (bsc#1064127): A source net restriction for _rpc_ services\n  was not taken into account for the implicitly added rules for port 111,\n  making the portmap service accessible to everyone in the affected zone when\n  the 'rpc' matching was used.\n","id":"SUSE-SU-2017:2935-1","modified":"2017-11-06T16:19:18Z","published":"2017-11-06T16:19:18Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20172935-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064127"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15638"}],"related":["CVE-2017-15638"],"summary":"Security update for SuSEfirewall2","upstream":["CVE-2017-15638"]}