SUSE 5022 Published by

A texlive-filesystem security update has been released for openSUSE Leap 15.1 to fix three security issues.



openSUSE Security Update: Security update for texlive-filesystem
______________________________________________________________________________

Announcement ID: openSUSE-SU-2020:0368-1
Rating: moderate
References: #1150556 #1155381 #1158910 #1159740
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________

An update that contains security fixes can now be installed.

Description:

This update for texlive-filesystem fixes the following issues:

Security issues fixed:

- Changed default user for ls-R files and font cache directories to user
nobody (bsc#1159740)
- Switched to rm instead of safe-rm or safe-rmdir to avoid race conditions
(bsc#1158910) .
- Made cron script more failsafe (bsc#1150556)

Non-security issue fixed:

- Refreshed font map files on update (bsc#1155381)

This update was imported from the SUSE:SLE-15:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-368=1


Package List:

- openSUSE Leap 15.1 (noarch):

texlive-collection-basic-2017.135.svn41616-lp151.8.3.1
texlive-collection-bibtexextra-2017.135.svn44385-lp151.8.3.1
texlive-collection-binextra-2017.135.svn44515-lp151.8.3.1
texlive-collection-context-2017.135.svn42330-lp151.8.3.1
texlive-collection-fontsextra-2017.135.svn43356-lp151.8.3.1
texlive-collection-fontsrecommended-2017.135.svn35830-lp151.8.3.1
texlive-collection-fontutils-2017.135.svn37105-lp151.8.3.1
texlive-collection-formatsextra-2017.135.svn44177-lp151.8.3.1
texlive-collection-games-2017.135.svn42992-lp151.8.3.1
texlive-collection-humanities-2017.135.svn42268-lp151.8.3.1
texlive-collection-langarabic-2017.135.svn44496-lp151.8.3.1
texlive-collection-langchinese-2017.135.svn42675-lp151.8.3.1
texlive-collection-langcjk-2017.135.svn43009-lp151.8.3.1
texlive-collection-langcyrillic-2017.135.svn44401-lp151.8.3.1
texlive-collection-langczechslovak-2017.135.svn32550-lp151.8.3.1
texlive-collection-langenglish-2017.135.svn43650-lp151.8.3.1
texlive-collection-langeuropean-2017.135.svn44414-lp151.8.3.1
texlive-collection-langfrench-2017.135.svn40375-lp151.8.3.1
texlive-collection-langgerman-2017.135.svn42045-lp151.8.3.1
texlive-collection-langgreek-2017.135.svn44192-lp151.8.3.1
texlive-collection-langitalian-2017.135.svn30372-lp151.8.3.1
texlive-collection-langjapanese-2017.135.svn44554-lp151.8.3.1
texlive-collection-langkorean-2017.135.svn42106-lp151.8.3.1
texlive-collection-langother-2017.135.svn44414-lp151.8.3.1
texlive-collection-langpolish-2017.135.svn44371-lp151.8.3.1
texlive-collection-langportuguese-2017.135.svn30962-lp151.8.3.1
texlive-collection-langspanish-2017.135.svn40587-lp151.8.3.1
texlive-collection-latex-2017.135.svn41614-lp151.8.3.1
texlive-collection-latexextra-2017.135.svn44544-lp151.8.3.1
texlive-collection-latexrecommended-2017.135.svn44177-lp151.8.3.1
texlive-collection-luatex-2017.135.svn44500-lp151.8.3.1
texlive-collection-mathscience-2017.135.svn44396-lp151.8.3.1
texlive-collection-metapost-2017.135.svn44297-lp151.8.3.1
texlive-collection-music-2017.135.svn40561-lp151.8.3.1
texlive-collection-pictures-2017.135.svn44395-lp151.8.3.1
texlive-collection-plaingeneric-2017.135.svn44177-lp151.8.3.1
texlive-collection-pstricks-2017.135.svn44460-lp151.8.3.1
texlive-collection-publishers-2017.135.svn44485-lp151.8.3.1
texlive-collection-xetex-2017.135.svn43059-lp151.8.3.1
texlive-devel-2017.135-lp151.8.3.1
texlive-extratools-2017.135-lp151.8.3.1
texlive-filesystem-2017.135-lp151.8.3.1
texlive-scheme-basic-2017.135.svn25923-lp151.8.3.1
texlive-scheme-context-2017.135.svn35799-lp151.8.3.1
texlive-scheme-full-2017.135.svn44177-lp151.8.3.1
texlive-scheme-gust-2017.135.svn44177-lp151.8.3.1
texlive-scheme-infraonly-2017.135.svn41515-lp151.8.3.1
texlive-scheme-medium-2017.135.svn44177-lp151.8.3.1
texlive-scheme-minimal-2017.135.svn13822-lp151.8.3.1
texlive-scheme-small-2017.135.svn41825-lp151.8.3.1
texlive-scheme-tetex-2017.135.svn44187-lp151.8.3.1

References:

https://bugzilla.suse.com/1150556
https://bugzilla.suse.com/1155381
https://bugzilla.suse.com/1158910
https://bugzilla.suse.com/1159740