<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for permissions</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:2280-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-07-09T14:29:17Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-07-09T14:29:17Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-07-09T14:29:17Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for permissions</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for permissions fixes the following issues:

- Fork package for 12-SP5 (bsc#1155939)
- make btmp root:utmp (bsc#1050467, bsc#1182899)
- pcp: remove no longer needed / conflicting entries (bsc#1171883). Fixes a potential security issue.
- do not follow symlinks that are the final path element (CVE-2020-8013, bsc#1163922)
- fix handling of relative directory symlinks in chkstat
- whitelist postgres sticky directories (bsc#1123886)
- fix regression where chkstat breaks without /proc available (bsc#1160764, bsc#1160594)
- fix capability handling when doing multiple permission changes at once (bsc#1161779,
- fix invalid free() when permfiles points to argv (bsc#1157198)
- the eror should be reported for permfiles[i], not argv[i], as these are not the same files. (bsc#1047247, bsc#1097665)
- fix /usr/sbin/pinger ownership to root:squid (bsc#1093414, CVE-2019-3688)
- fix privilege escalation through untrusted symlinks (bsc#1150734, CVE-2019-3690)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Container suse/ltss/sle12.5/sles12sp5:latest-2021-2280,Container suse/sles12sp5:latest-2021-2280,Image SLES12-SP5-Azure-BYOS-2021-2280,Image SLES12-SP5-Azure-Basic-On-Demand-2021-2280,Image SLES12-SP5-Azure-HPC-BYOS-2021-2280,Image SLES12-SP5-Azure-HPC-On-Demand-2021-2280,Image SLES12-SP5-Azure-SAP-BYOS-2021-2280,Image SLES12-SP5-Azure-SAP-On-Demand-2021-2280,Image SLES12-SP5-Azure-Standard-On-Demand-2021-2280,Image SLES12-SP5-EC2-BYOS-2021-2280,Image SLES12-SP5-EC2-ECS-On-Demand-2021-2280,Image SLES12-SP5-EC2-On-Demand-2021-2280,Image SLES12-SP5-EC2-SAP-BYOS-2021-2280,Image SLES12-SP5-EC2-SAP-On-Demand-2021-2280,Image SLES12-SP5-GCE-BYOS-2021-2280,Image SLES12-SP5-GCE-On-Demand-2021-2280,Image SLES12-SP5-GCE-SAP-BYOS-2021-2280,Image SLES12-SP5-GCE-SAP-On-Demand-2021-2280,Image SLES12-SP5-OCI-BYOS-BYOS-2021-2280,Image SLES12-SP5-OCI-BYOS-SAP-BYOS-2021-2280,Image SLES12-SP5-SAP-Azure-LI-BYOS-Production-2021-2280,Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production-2021-2280,SUSE-2021-2280,SUSE-SLE-SERVER-12-SP5-2021-2280</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20212280-1/</URL>
      <Description>Link for SUSE-SU-2021:2280-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-July/009118.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:2280-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1047247</URL>
      <Description>SUSE Bug 1047247</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1050467</URL>
      <Description>SUSE Bug 1050467</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1093414</URL>
      <Description>SUSE Bug 1093414</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1097665</URL>
      <Description>SUSE Bug 1097665</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1123886</URL>
      <Description>SUSE Bug 1123886</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1150734</URL>
      <Description>SUSE Bug 1150734</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1155939</URL>
      <Description>SUSE Bug 1155939</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1157198</URL>
      <Description>SUSE Bug 1157198</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1160594</URL>
      <Description>SUSE Bug 1160594</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1160764</URL>
      <Description>SUSE Bug 1160764</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1161779</URL>
      <Description>SUSE Bug 1161779</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1163922</URL>
      <Description>SUSE Bug 1163922</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1171883</URL>
      <Description>SUSE Bug 1171883</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182899</URL>
      <Description>SUSE Bug 1182899</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-3688/</URL>
      <Description>SUSE CVE CVE-2019-3688 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-3690/</URL>
      <Description>SUSE CVE CVE-2019-3690 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8013/</URL>
      <Description>SUSE CVE CVE-2020-8013 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="Container suse/ltss/sle12.5/sles12sp5:latest">
      <Branch Type="Product Name" Name="Container suse/ltss/sle12.5/sles12sp5:latest">
        <FullProductName ProductID="Container suse/ltss/sle12.5/sles12sp5:latest">Container suse/ltss/sle12.5/sles12sp5:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/sles12sp5:latest">
      <Branch Type="Product Name" Name="Container suse/sles12sp5:latest">
        <FullProductName ProductID="Container suse/sles12sp5:latest">Container suse/sles12sp5:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS">Image SLES12-SP5-Azure-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-Basic-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-Basic-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-Basic-On-Demand">Image SLES12-SP5-Azure-Basic-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-HPC-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-HPC-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS">Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-HPC-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-HPC-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-On-Demand">Image SLES12-SP5-Azure-HPC-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS">Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand">Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-Standard-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-Standard-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-Standard-On-Demand">Image SLES12-SP5-Azure-Standard-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS">Image SLES12-SP5-EC2-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand">Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand">Image SLES12-SP5-EC2-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS">Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand">Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS">Image SLES12-SP5-GCE-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-GCE-On-Demand">Image SLES12-SP5-GCE-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS">Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand">Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-OCI-BYOS-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-OCI-BYOS-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-OCI-BYOS-BYOS">Image SLES12-SP5-OCI-BYOS-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-OCI-BYOS-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-OCI-BYOS-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-OCI-BYOS-SAP-BYOS">Image SLES12-SP5-OCI-BYOS-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5" CPE="cpe:/o:suse:sles:12:sp5">SUSE Linux Enterprise Server 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5" CPE="cpe:/o:suse:sles_sap:12:sp5">SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="permissions-20170707-6.4.1">
      <FullProductName ProductID="permissions-20170707-6.4.1">permissions-20170707-6.4.1</FullProductName>
    </Branch>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/ltss/sle12.5/sles12sp5:latest">
      <FullProductName ProductID="Container suse/ltss/sle12.5/sles12sp5:latest:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Container suse/ltss/sle12.5/sles12sp5:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sles12sp5:latest">
      <FullProductName ProductID="Container suse/sles12sp5:latest:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Container suse/sles12sp5:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-Basic-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-Basic-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-Azure-Basic-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-Azure-HPC-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-Standard-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-Standard-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-Azure-Standard-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-EC2-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-ECS-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-EC2-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-GCE-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-OCI-BYOS-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-OCI-BYOS-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-OCI-BYOS-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-OCI-BYOS-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-OCI-BYOS-SAP-BYOS:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-OCI-BYOS-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="permissions-20170707-6.4.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:permissions-20170707-6.4.1">permissions-20170707-6.4.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary</Note>
    </Notes>
    <CVE>CVE-2019-3688</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/ltss/sle12.5/sles12sp5:latest:permissions-20170707-6.4.1</ProductID>
        <ProductID>Container suse/sles12sp5:latest:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Basic-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Standard-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-OCI-BYOS-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-OCI-BYOS-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:permissions-20170707-6.4.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:permissions-20170707-6.4.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:permissions-20170707-6.4.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.6</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:C/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.1</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20212280-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-3688.html</URL>
        <Description>CVE-2019-3688</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1093414</URL>
        <Description>SUSE Bug 1093414</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1149108</URL>
        <Description>SUSE Bug 1149108</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.</Note>
    </Notes>
    <CVE>CVE-2019-3690</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/ltss/sle12.5/sles12sp5:latest:permissions-20170707-6.4.1</ProductID>
        <ProductID>Container suse/sles12sp5:latest:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Basic-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Standard-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-OCI-BYOS-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-OCI-BYOS-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:permissions-20170707-6.4.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:permissions-20170707-6.4.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:permissions-20170707-6.4.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>7.2</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:C/I:C/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.8</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20212280-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-3690.html</URL>
        <Description>CVE-2019-3690</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1148336</URL>
        <Description>SUSE Bug 1148336</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1150734</URL>
        <Description>SUSE Bug 1150734</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1157880</URL>
        <Description>SUSE Bug 1157880</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1157883</URL>
        <Description>SUSE Bug 1157883</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1160594</URL>
        <Description>SUSE Bug 1160594</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1160764</URL>
        <Description>SUSE Bug 1160764</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1163922</URL>
        <Description>SUSE Bug 1163922</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. This issue affects: SUSE Linux Enterprise Server 12 permissions versions prior to 2015.09.28.1626-17.27.1. SUSE Linux Enterprise Server 15 permissions versions prior to 20181116-9.23.1. SUSE Linux Enterprise Server 11 permissions versions prior to 2013.1.7-0.6.12.1.</Note>
    </Notes>
    <CVE>CVE-2020-8013</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/ltss/sle12.5/sles12sp5:latest:permissions-20170707-6.4.1</ProductID>
        <ProductID>Container suse/sles12sp5:latest:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Basic-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Standard-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-OCI-BYOS-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-OCI-BYOS-SAP-BYOS:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:permissions-20170707-6.4.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:permissions-20170707-6.4.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:permissions-20170707-6.4.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:permissions-20170707-6.4.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>1.9</BaseScoreV2>
        <VectorV2>AV:L/AC:M/Au:N/C:N/I:P/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20212280-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8013.html</URL>
        <Description>CVE-2020-8013</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1163922</URL>
        <Description>SUSE Bug 1163922</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
