<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for SUSE Manager Client Tools</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2019:14163-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-09-05T15:32:15Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-09-05T15:32:15Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-09-05T15:32:15Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for SUSE Manager Client Tools</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update fixes the following issues:

mgr-cfg:

- Ensure bytes type when using hashlib to avoid traceback (bsc#1138822)

mgr-daemon:

- Fix systemd timer configuration on SLE12 (bsc#1142038)

mgr-osad:

- Fix obsolete for old osad packages, to allow installing mgr-osad
  even by using osad at yum/zyppper install (bsc#1139453)
- Ensure bytes type when using hashlib to avoid traceback (bsc#1138822)

mgr-virtualization:

- Fix missing python 3 ugettext (bsc#1138494)
- Fix package dependencies to prevent file conflict (bsc#1143856)

rhnlib:

- Add SNI support for clients
- Fix initialize ssl connection (bsc#1144155)
- Fix bootstrapping SLE11SP4 trad client with SSL enabled (bsc#1148177)
    
python-gzipstream:

- SPEC cleanup
- add makefile and pylint configuration
- Add Uyuni URL to package
- Bump version to 4.0.0 (bsc#1104034)
- Fix copyright for the package specfile (bsc#1103696)

spacecmd:

- Bugfix: referenced variable before assignment.
- Bugfix: 'dict' object has no attribute 'iteritems' (bsc#1135881)
- Add unit tests for custominfo, snippet, scap, ssm, cryptokey and distribution
- Fix missing runtime dependencies that made spacecmd return old versions of
  packages in some cases, even if newer ones were available (bsc#1148311)


spacewalk-backend:

- Do not overwrite comps and module data with older versions
- Fix issue with 'dists' keyword in url hostname
- Import packages from all collections of a patch not just first one
- Ensure bytes type when using hashlib to avoid traceback
  on XMLRPC call to 'registration.register_osad' (bsc#1138822)
- Do not duplicate 'http://' protocol when using proxies with 'deb'
  repositories (bsc#1138313)
- Fix reposync when dealing with RedHat CDN (bsc#1138358)
- Fix for CVE-2019-10136. An attacker with a valid, but expired,
  authenticated set of headers could move some digits around,
  artificially extending the session validity without modifying
  the checksum. (bsc#1136480)
- Prevent FileNotFoundError: repomd.xml.key traceback (bsc#1137940)
- Add journalctl output to spacewalk-debug tarballs
- Prevent unnecessary triggering of channel-repodata tasks when GPG
  signing is disabled (bsc#1137715)
- Fix spacewalk-repo-sync for Ubuntu repositories in mirror case (bsc#1136029)
- Add support for ULN repositories on new Zypper based reposync.
- Don't skip Deb package tags on package import (bsc#1130040)
- For backend-libs subpackages, exclude files for the server
  (already part of spacewalk-backend) to avoid conflicts (bsc#1148125)
- prevent duplicate key violates on repo-sync with long changelog
  entries (bsc#1144889)

spacewalk-remote-utils:

- Add RHEL8

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">slesctsp3-client-tools-201907-14163,slesctsp4-client-tools-201907-14163</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2019/suse-su-201914163-1/</URL>
      <Description>Link for SUSE-SU-2019:14163-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2019-September/005884.html</URL>
      <Description>E-Mail link for SUSE-SU-2019:14163-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1103696</URL>
      <Description>SUSE Bug 1103696</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1104034</URL>
      <Description>SUSE Bug 1104034</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1130040</URL>
      <Description>SUSE Bug 1130040</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1135881</URL>
      <Description>SUSE Bug 1135881</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1136029</URL>
      <Description>SUSE Bug 1136029</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1136480</URL>
      <Description>SUSE Bug 1136480</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1137715</URL>
      <Description>SUSE Bug 1137715</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1137940</URL>
      <Description>SUSE Bug 1137940</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138313</URL>
      <Description>SUSE Bug 1138313</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138358</URL>
      <Description>SUSE Bug 1138358</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138494</URL>
      <Description>SUSE Bug 1138494</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138822</URL>
      <Description>SUSE Bug 1138822</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1139453</URL>
      <Description>SUSE Bug 1139453</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1142038</URL>
      <Description>SUSE Bug 1142038</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1143856</URL>
      <Description>SUSE Bug 1143856</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1144155</URL>
      <Description>SUSE Bug 1144155</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1144889</URL>
      <Description>SUSE Bug 1144889</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1148125</URL>
      <Description>SUSE Bug 1148125</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1148177</URL>
      <Description>SUSE Bug 1148177</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1148311</URL>
      <Description>SUSE Bug 1148311</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10136/</URL>
      <Description>SUSE CVE CVE-2019-10136 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS" CPE="cpe:/a:suse:sle-clienttools:11:sp3">SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS" CPE="cpe:/a:suse:sle-clienttools:11:sp4">SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="mgr-cfg-4.0.9-5.6.3">
      <FullProductName ProductID="mgr-cfg-4.0.9-5.6.3">mgr-cfg-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mgr-cfg-actions-4.0.9-5.6.3">
      <FullProductName ProductID="mgr-cfg-actions-4.0.9-5.6.3">mgr-cfg-actions-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mgr-cfg-client-4.0.9-5.6.3">
      <FullProductName ProductID="mgr-cfg-client-4.0.9-5.6.3">mgr-cfg-client-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mgr-cfg-management-4.0.9-5.6.3">
      <FullProductName ProductID="mgr-cfg-management-4.0.9-5.6.3">mgr-cfg-management-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mgr-daemon-4.0.7-5.8.2">
      <FullProductName ProductID="mgr-daemon-4.0.7-5.8.2">mgr-daemon-4.0.7-5.8.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mgr-osad-4.0.9-5.6.2">
      <FullProductName ProductID="mgr-osad-4.0.9-5.6.2">mgr-osad-4.0.9-5.6.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mgr-virtualization-host-4.0.8-5.8.3">
      <FullProductName ProductID="mgr-virtualization-host-4.0.8-5.8.3">mgr-virtualization-host-4.0.8-5.8.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-cfg-4.0.9-5.6.3">
      <FullProductName ProductID="python2-mgr-cfg-4.0.9-5.6.3">python2-mgr-cfg-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-cfg-actions-4.0.9-5.6.3">
      <FullProductName ProductID="python2-mgr-cfg-actions-4.0.9-5.6.3">python2-mgr-cfg-actions-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-cfg-client-4.0.9-5.6.3">
      <FullProductName ProductID="python2-mgr-cfg-client-4.0.9-5.6.3">python2-mgr-cfg-client-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-cfg-management-4.0.9-5.6.3">
      <FullProductName ProductID="python2-mgr-cfg-management-4.0.9-5.6.3">python2-mgr-cfg-management-4.0.9-5.6.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-osa-common-4.0.9-5.6.2">
      <FullProductName ProductID="python2-mgr-osa-common-4.0.9-5.6.2">python2-mgr-osa-common-4.0.9-5.6.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-osad-4.0.9-5.6.2">
      <FullProductName ProductID="python2-mgr-osad-4.0.9-5.6.2">python2-mgr-osad-4.0.9-5.6.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-virtualization-common-4.0.8-5.8.3">
      <FullProductName ProductID="python2-mgr-virtualization-common-4.0.8-5.8.3">python2-mgr-virtualization-common-4.0.8-5.8.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-mgr-virtualization-host-4.0.8-5.8.3">
      <FullProductName ProductID="python2-mgr-virtualization-host-4.0.8-5.8.3">python2-mgr-virtualization-host-4.0.8-5.8.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python2-rhnlib-4.0.11-12.16.1">
      <FullProductName ProductID="python2-rhnlib-4.0.11-12.16.1">python2-rhnlib-4.0.11-12.16.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacecmd-4.0.14-18.51.1">
      <FullProductName ProductID="spacecmd-4.0.14-18.51.1">spacecmd-4.0.14-18.51.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-libs-4.0.25-28.42.1">
      <FullProductName ProductID="spacewalk-backend-libs-4.0.25-28.42.1">spacewalk-backend-libs-4.0.25-28.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-remote-utils-4.0.5-6.12.2">
      <FullProductName ProductID="spacewalk-remote-utils-4.0.5-6.12.2">spacewalk-remote-utils-4.0.5-6.12.2</FullProductName>
    </Branch>
    <Relationship ProductReference="mgr-cfg-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-4.0.9-5.6.3">mgr-cfg-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-cfg-actions-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-actions-4.0.9-5.6.3">mgr-cfg-actions-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-cfg-client-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-client-4.0.9-5.6.3">mgr-cfg-client-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-cfg-management-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-management-4.0.9-5.6.3">mgr-cfg-management-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-daemon-4.0.7-5.8.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-daemon-4.0.7-5.8.2">mgr-daemon-4.0.7-5.8.2 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-osad-4.0.9-5.6.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-osad-4.0.9-5.6.2">mgr-osad-4.0.9-5.6.2 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-virtualization-host-4.0.8-5.8.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-virtualization-host-4.0.8-5.8.3">mgr-virtualization-host-4.0.8-5.8.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-4.0.9-5.6.3">python2-mgr-cfg-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-actions-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-actions-4.0.9-5.6.3">python2-mgr-cfg-actions-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-client-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-client-4.0.9-5.6.3">python2-mgr-cfg-client-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-management-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-management-4.0.9-5.6.3">python2-mgr-cfg-management-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-osa-common-4.0.9-5.6.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-osa-common-4.0.9-5.6.2">python2-mgr-osa-common-4.0.9-5.6.2 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-osad-4.0.9-5.6.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-osad-4.0.9-5.6.2">python2-mgr-osad-4.0.9-5.6.2 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-virtualization-common-4.0.8-5.8.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-virtualization-common-4.0.8-5.8.3">python2-mgr-virtualization-common-4.0.8-5.8.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-virtualization-host-4.0.8-5.8.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-virtualization-host-4.0.8-5.8.3">python2-mgr-virtualization-host-4.0.8-5.8.3 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-rhnlib-4.0.11-12.16.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-rhnlib-4.0.11-12.16.1">python2-rhnlib-4.0.11-12.16.1 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacecmd-4.0.14-18.51.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:spacecmd-4.0.14-18.51.1">spacecmd-4.0.14-18.51.1 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-libs-4.0.25-28.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:spacewalk-backend-libs-4.0.25-28.42.1">spacewalk-backend-libs-4.0.25-28.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-remote-utils-4.0.5-6.12.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:spacewalk-remote-utils-4.0.5-6.12.2">spacewalk-remote-utils-4.0.5-6.12.2 as a component of SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-cfg-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-4.0.9-5.6.3">mgr-cfg-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-cfg-actions-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-actions-4.0.9-5.6.3">mgr-cfg-actions-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-cfg-client-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-client-4.0.9-5.6.3">mgr-cfg-client-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-cfg-management-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-management-4.0.9-5.6.3">mgr-cfg-management-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-daemon-4.0.7-5.8.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-daemon-4.0.7-5.8.2">mgr-daemon-4.0.7-5.8.2 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-osad-4.0.9-5.6.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-osad-4.0.9-5.6.2">mgr-osad-4.0.9-5.6.2 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="mgr-virtualization-host-4.0.8-5.8.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-virtualization-host-4.0.8-5.8.3">mgr-virtualization-host-4.0.8-5.8.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-4.0.9-5.6.3">python2-mgr-cfg-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-actions-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-actions-4.0.9-5.6.3">python2-mgr-cfg-actions-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-client-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-client-4.0.9-5.6.3">python2-mgr-cfg-client-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-cfg-management-4.0.9-5.6.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-management-4.0.9-5.6.3">python2-mgr-cfg-management-4.0.9-5.6.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-osa-common-4.0.9-5.6.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-osa-common-4.0.9-5.6.2">python2-mgr-osa-common-4.0.9-5.6.2 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-osad-4.0.9-5.6.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-osad-4.0.9-5.6.2">python2-mgr-osad-4.0.9-5.6.2 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-virtualization-common-4.0.8-5.8.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-virtualization-common-4.0.8-5.8.3">python2-mgr-virtualization-common-4.0.8-5.8.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-mgr-virtualization-host-4.0.8-5.8.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-virtualization-host-4.0.8-5.8.3">python2-mgr-virtualization-host-4.0.8-5.8.3 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python2-rhnlib-4.0.11-12.16.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-rhnlib-4.0.11-12.16.1">python2-rhnlib-4.0.11-12.16.1 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacecmd-4.0.14-18.51.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:spacecmd-4.0.14-18.51.1">spacecmd-4.0.14-18.51.1 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-libs-4.0.25-28.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:spacewalk-backend-libs-4.0.25-28.42.1">spacewalk-backend-libs-4.0.25-28.42.1 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-remote-utils-4.0.5-6.12.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:spacewalk-remote-utils-4.0.5-6.12.2">spacewalk-remote-utils-4.0.5-6.12.2 as a component of SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.</Note>
    </Notes>
    <CVE>CVE-2019-10136</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-actions-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-client-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-cfg-management-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-daemon-4.0.7-5.8.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-osad-4.0.9-5.6.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:mgr-virtualization-host-4.0.8-5.8.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-actions-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-client-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-cfg-management-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-osa-common-4.0.9-5.6.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-osad-4.0.9-5.6.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-virtualization-common-4.0.8-5.8.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-mgr-virtualization-host-4.0.8-5.8.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:python2-rhnlib-4.0.11-12.16.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:spacecmd-4.0.14-18.51.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:spacewalk-backend-libs-4.0.25-28.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-CLIENT-TOOLS:spacewalk-remote-utils-4.0.5-6.12.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-actions-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-client-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-cfg-management-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-daemon-4.0.7-5.8.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-osad-4.0.9-5.6.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:mgr-virtualization-host-4.0.8-5.8.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-actions-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-client-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-cfg-management-4.0.9-5.6.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-osa-common-4.0.9-5.6.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-osad-4.0.9-5.6.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-virtualization-common-4.0.8-5.8.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-mgr-virtualization-host-4.0.8-5.8.3</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:python2-rhnlib-4.0.11-12.16.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:spacecmd-4.0.14-18.51.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:spacewalk-backend-libs-4.0.25-28.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS:spacewalk-remote-utils-4.0.5-6.12.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2019/suse-su-201914163-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10136.html</URL>
        <Description>CVE-2019-10136</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1136480</URL>
        <Description>SUSE Bug 1136480</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
