|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: hdf5: multiple CVEs | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Carlos López <carlos.lopez> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | NEW --- | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | badshah400, hpc-bugs, stoyan.manolov |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/404981/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-29158:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29159:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29160:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29161:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29162:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29163:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29164:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29165:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-29166:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32605:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32606:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32607:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32608:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32609:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32610:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32611:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32612:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32613:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32614:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32615:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32616:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32617:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32618:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32619:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32620:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32621:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32622:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32623:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-32624:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-33873:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-33874:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-33875:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-33876:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSSv3.1:SUSE:CVE-2024-33877:5.7:(AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Carlos López
2024-05-13 07:26:02 UTC
The Maintenance incidents are: 12SP2: 34244 15SP2: 27829 15SP3: 34207 15SP4: 28369 Assigning back to the security team. SUSE-SU-2024:2105-1: An update that solves 13 vulnerabilities can now be installed. Category: security (important) Bug References: 1133222, 1224158 CVE References: CVE-2017-17507, CVE-2018-11205, CVE-2024-29158, CVE-2024-29161, CVE-2024-29166, CVE-2024-32608, CVE-2024-32610, CVE-2024-32614, CVE-2024-32619, CVE-2024-32620, CVE-2024-33873, CVE-2024-33874, CVE-2024-33875 Maintenance Incident: [SUSE:Maintenance:34244](https://smelt.suse.de/incident/34244/) Sources used: HPC Module 12 (src): hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-3.24.1, hdf5_1_10_11-gnu-hpc-1.10.11-3.24.1, hdf5_1_10_11-gnu-openmpi1-hpc-1.10.11-3.24.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2024:2195-1: An update that solves 13 vulnerabilities can now be installed. Category: security (important) Bug References: 1224158 CVE References: CVE-2017-17507, CVE-2018-11205, CVE-2024-29158, CVE-2024-29161, CVE-2024-29166, CVE-2024-32608, CVE-2024-32610, CVE-2024-32614, CVE-2024-32619, CVE-2024-32620, CVE-2024-33873, CVE-2024-33874, CVE-2024-33875 Maintenance Incident: [SUSE:Maintenance:34207](https://smelt.suse.de/incident/34207/) Sources used: openSUSE Leap 15.3 (src): pmix-3.2.3-150300.3.10.1 openSUSE Leap 15.4 (src): hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1 openSUSE Leap 15.5 (src): mvapich2-psm-2.3.7-150500.3.2.1, mpich-ofi_4_0_2-gnu-hpc-testsuite-4.0.2-150500.3.2.1, mpich_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, mpich-ofi-4.0.2-150500.3.2.1, mvapich2_2_3_7-gnu-hpc-2.3.7-150500.3.2.1, mvapich2-psm2-2.3.7-150500.3.2.1, lua53-luaposix-34.1.1-150200.3.5.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, lua53-luaterm-0.07-150000.5.5.1, lua51-luaterm-0.07-150000.5.5.1, lua51-luaposix-34.1.1-150200.3.5.1, mpich-testsuite-4.0.2-150500.3.2.1, openmpi4-testsuite-4.1.4-150500.3.2.1, mvapich2-psm2_2_3_7-gnu-hpc-2.3.7-150500.3.2.1, mpich-ofi-testsuite-4.0.2-150500.3.2.1, mpich-ofi_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, pmix-3.2.3-150300.3.10.1, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, mpich_4_0_2-gnu-hpc-testsuite-4.0.2-150500.3.2.1, openmpi_4_1_4-gnu-hpc-testsuite-4.1.4-150500.3.2.1, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, mvapich2-2.3.7-150500.3.2.1, mvapich2-psm_2_3_7-gnu-hpc-2.3.7-150500.3.2.1, openmpi4-4.1.4-150500.3.2.1, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, openmpi_4_1_4-gnu-hpc-4.1.4-150500.3.2.1, mpich-4.0.2-150500.3.2.1 openSUSE Leap 15.6 (src): mvapich2-psm-2.3.7-150500.3.2.1, mpich-ofi_4_1_2-gnu-hpc-4.1.2-150600.3.2.1, mpich_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, lua53-luaterm-0.07-150000.5.5.1, mpich-ofi-testsuite-4.1.2-150600.3.2.2, lua51-luaterm-0.07-150000.5.5.1, lua51-luaposix-34.1.1-150200.3.5.1, mpich-testsuite-4.1.2-150600.3.2.2, mvapich2-psm2-2.3.7-150600.9.2.1, mpich-ofi_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, mvapich2_2_3_7-gnu-hpc-2.3.7-150600.9.2.2, pmix-3.2.3-150300.3.10.1, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, openmpi_4_1_4-gnu-hpc-4.1.4-150500.3.2.1, openmpi4-testsuite-4.1.6-150600.3.2.1, lua53-luaposix-34.1.1-150200.3.5.1, mpich-ofi_4_1_2-gnu-hpc-testsuite-4.1.2-150600.3.2.2, mpich_4_1_2-gnu-hpc-testsuite-4.1.2-150600.3.2.2, hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, mpich-ofi-4.1.2-150600.3.2.1, mvapich2-2.3.7-150600.9.2.1, openmpi_4_1_6-gnu-hpc-4.1.6-150600.3.2.1, mpich_4_1_2-gnu-hpc-4.1.2-150600.3.2.1, openmpi_4_1_4-gnu-hpc-testsuite-4.1.4-150500.3.2.1, openmpi_4_1_6-gnu-hpc-testsuite-4.1.6-150600.3.2.1, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, mvapich2-psm_2_3_7-gnu-hpc-2.3.7-150500.3.2.1, mvapich2_2_3_7-gnu-hpc-2.3.7-150600.9.2.1, mpich-4.1.2-150600.3.2.1, mvapich2-psm2_2_3_7-gnu-hpc-2.3.7-150600.9.2.1, openmpi4-4.1.6-150600.3.2.1 HPC Module 15-SP5 (src): mpich-ofi_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, mpich_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, pmix-3.2.3-150300.3.10.1, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, mvapich2_2_3_7-gnu-hpc-2.3.7-150500.3.2.1, lua53-luaposix-34.1.1-150200.3.5.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, lua53-luaterm-0.07-150000.5.5.1, mvapich2-psm_2_3_7-gnu-hpc-2.3.7-150500.3.2.1, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, openmpi_4_1_4-gnu-hpc-4.1.4-150500.3.2.1, mvapich2-psm2_2_3_7-gnu-hpc-2.3.7-150500.3.2.1 HPC Module 15-SP6 (src): hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, mpich-ofi_4_1_2-gnu-hpc-4.1.2-150600.3.2.1, pmix-3.2.3-150300.3.10.1, openmpi_4_1_6-gnu-hpc-4.1.6-150600.3.2.1, mpich_4_1_2-gnu-hpc-4.1.2-150600.3.2.1, lua53-luaposix-34.1.1-150200.3.5.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, lua53-luaterm-0.07-150000.5.5.1, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, mvapich2_2_3_7-gnu-hpc-2.3.7-150600.9.2.1, mvapich2-psm2_2_3_7-gnu-hpc-2.3.7-150600.9.2.1 SUSE Package Hub 15 15-SP5 (src): mpich-ofi_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, mpich_4_0_2-gnu-hpc-4.0.2-150500.3.2.1, pmix-3.2.3-150300.3.10.1, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, mvapich2_2_3_7-gnu-hpc-2.3.7-150500.3.2.1, lua53-luaposix-34.1.1-150200.3.5.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, lua53-luaterm-0.07-150000.5.5.1, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, openmpi_4_1_4-gnu-hpc-4.1.4-150500.3.2.1, lua53-luafilesystem-1.7.0-150000.3.5.1 SUSE Package Hub 15 15-SP6 (src): hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, mpich-ofi_4_1_2-gnu-hpc-4.1.2-150600.3.2.1, pmix-3.2.3-150300.3.10.1, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, openmpi_4_1_6-gnu-hpc-4.1.6-150600.3.2.1, mpich_4_1_2-gnu-hpc-4.1.2-150600.3.2.1, lua53-luaposix-34.1.1-150200.3.5.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, lua53-luaterm-0.07-150000.5.5.1, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, mvapich2_2_3_7-gnu-hpc-2.3.7-150600.9.2.1, lua53-luafilesystem-1.7.0-150000.3.5.1 Server Applications Module 15-SP5 (src): mvapich2-2.3.7-150500.3.2.1, openmpi4-4.1.4-150500.3.2.1, mvapich2-psm-2.3.7-150500.3.2.1, mpich-4.0.2-150500.3.2.1, mpich-ofi-4.0.2-150500.3.2.1, mvapich2-psm2-2.3.7-150500.3.2.1 Server Applications Module 15-SP6 (src): mvapich2-psm2-2.3.7-150600.9.2.1, mpich-ofi-4.1.2-150600.3.2.1, mvapich2-2.3.7-150600.9.2.1, mpich-4.1.2-150600.3.2.1, openmpi4-4.1.6-150600.3.2.1 SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): lua53-luaterm-0.07-150000.5.5.1, lua53-luaposix-34.1.1-150200.3.5.1, lua53-luafilesystem-1.7.0-150000.3.5.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): lua53-luaterm-0.07-150000.5.5.1, lua53-luaposix-34.1.1-150200.3.5.1, lua53-luafilesystem-1.7.0-150000.3.5.1, pmix-3.2.3-150300.3.10.1 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, pmix-3.2.3-150300.3.10.1, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, lua53-luaposix-34.1.1-150200.3.5.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, lua53-luaterm-0.07-150000.5.5.1, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, lua53-luafilesystem-1.7.0-150000.3.5.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): hdf5_1_10_11-gnu-mvapich2-hpc-1.10.11-150400.3.17.2, pmix-3.2.3-150300.3.10.1, hdf5_1_10_11-gnu-openmpi3-hpc-1.10.11-150400.3.17.2, lua53-luaposix-34.1.1-150200.3.5.1, hdf5_1_10_11-gnu-mpich-hpc-1.10.11-150400.3.17.2, hdf5_1_10_11-gnu-hpc-1.10.11-150400.3.17.1, lua53-luaterm-0.07-150000.5.5.1, hdf5_1_10_11-gnu-openmpi4-hpc-1.10.11-150400.3.17.2, lua53-luafilesystem-1.7.0-150000.3.5.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. |