Hello community, here is the log from the commit of package icinga2 for openSUSE:Factory checked in at 2020-10-20 16:09:54 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/icinga2 (Old) and /work/SRC/openSUSE:Factory/.icinga2.new.3486 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "icinga2" Tue Oct 20 16:09:54 2020 rev:31 rq:842560 version:2.12.1 Changes: -------- --- /work/SRC/openSUSE:Factory/icinga2/icinga2.changes 2020-10-18 16:32:11.560778474 +0200 +++ /work/SRC/openSUSE:Factory/.icinga2.new.3486/icinga2.changes 2020-10-20 16:20:26.990295035 +0200 @@ -1,0 +2,7 @@ +Mon Oct 19 13:22:40 UTC 2020 - ecsos <ec...@opensuse.org> + +- Info that since version 2.12.0 following security issue is fixed: + prepare-dirs script allows for symlink attack in the icinga user + context. boo#1172171 (CVE-2020-14004) + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------