openSUSE Security Update : erlang (openSUSE-2017-1358) (ROBOT)

critical Nessus Plugin ID 105241

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for erlang fixes security issues and bugs.

The following vulnerabilities were addressed :

- CVE-2017-1000385: Harden against the Bleichenbacher attacher against RSA

- CVE-2016-10253: Heap overflow through regular expressions (bsc#1030062)

In addition Erlang was updated to version 18.3.4.6, containing a number of upstream bug fixes and improvements.

Solution

Update the affected erlang packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1030062

Plugin Details

Severity: Critical

ID: 105241

File Name: openSUSE-2017-1358.nasl

Version: 3.5

Type: local

Agent: unix

Published: 12/14/2017

Updated: 1/19/2021

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:erlang-et, p-cpe:/a:novell:opensuse:erlang-wx-src, p-cpe:/a:novell:opensuse:erlang-src, p-cpe:/a:novell:opensuse:erlang-diameter-src, p-cpe:/a:novell:opensuse:erlang-observer-src, p-cpe:/a:novell:opensuse:erlang-et-src, p-cpe:/a:novell:opensuse:erlang-jinterface-src, p-cpe:/a:novell:opensuse:erlang-debuginfo, p-cpe:/a:novell:opensuse:erlang-diameter, p-cpe:/a:novell:opensuse:erlang-debugger-src, p-cpe:/a:novell:opensuse:erlang-gs-src, p-cpe:/a:novell:opensuse:erlang-observer, p-cpe:/a:novell:opensuse:erlang-dialyzer-debuginfo, p-cpe:/a:novell:opensuse:erlang-dialyzer-src, p-cpe:/a:novell:opensuse:erlang-jinterface, p-cpe:/a:novell:opensuse:erlang-gs, p-cpe:/a:novell:opensuse:erlang, p-cpe:/a:novell:opensuse:erlang-debugger, p-cpe:/a:novell:opensuse:erlang-reltool, p-cpe:/a:novell:opensuse:erlang-reltool-src, p-cpe:/a:novell:opensuse:erlang-wx-debuginfo, p-cpe:/a:novell:opensuse:erlang-epmd-debuginfo, cpe:/o:novell:opensuse:42.2, p-cpe:/a:novell:opensuse:erlang-debugsource, cpe:/o:novell:opensuse:42.3, p-cpe:/a:novell:opensuse:erlang-dialyzer, p-cpe:/a:novell:opensuse:erlang-wx, p-cpe:/a:novell:opensuse:erlang-epmd

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 12/8/2017

Reference Information

CVE: CVE-2016-10253, CVE-2017-1000385