Synopsis
The remote SUSE host is missing a security update.
Description
The remote SUSE Linux SLES15 / SLES_SAP15 / openSUSE 15 host has packages installed that are affected by a vulnerability as referenced in the SUSE-SU-2024:4416-1 advisory.
Updated to version 1.2
- Fix actions using the 'free' command
- Fix buffer accounting when generating metric XML
- Change actions to retrieve vendor and product info
- Add a 'unit' attribute to the metrics element
- vif-stats.py: convert to Python3
- conf: Update the 'VirtualizationVendor' action to strip any URLs that may follow the vendor name (bsc#1230961)
- Fix virtio transport to work with libvirt >= 9.7.0
- Added hardening to systemd service (bsc#1181400)
- spec: Don't replace user-modified dtd in /etc/vhostmd/ (bsc#1154838)
- Relax virtio requirement in config file (bsc#1152803)
Updated to version 1.1 (bsc#1129772)
- Merge libserialclient with libmetrics
- Misc bug fixes and improvements
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
Solution
Update the affected libmetrics-devel, libmetrics0, vhostmd and / or vm-dump-metrics packages.
Plugin Details
File Name: suse_SU-2024-4416-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Vulnerability Information
CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:vhostmd, p-cpe:/a:novell:suse_linux:vm-dump-metrics
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 12/24/2024
Vulnerability Publication Date: 12/24/2024
Reference Information
SuSE: SUSE-SU-2024:4416-1