{"id":"SUSE-SU-2020:1296-1","summary":"Security update for autoyast2","details":"This update for autoyast2 to version 4.1.15 fixes the following issues:\n\nSecurity issue fixed:\n\n- CVE-2019-18905: Removed all '--gpg-auto-import-keys' options from zypper commands (bsc#1140711).\n\nNon-security issue fixed:\n\n- Fix desktop files updating some icons and groups (bsc#1168123).\n- Restored some missing icons (bsc#1168123, bsc#1109310 and bsc#1168281).\n- Service for init scripts: Try to start 'network-online.target' \n  before starting the autoyast init scripts in order to get a working\n  network (bsc#1164105).\n- Always re-probe storage after pre-scripts (bsc#1170082, bsc#1133045).\n","modified":"2026-02-04T03:51:58.251294Z","published":"2020-05-18T05:42:00Z","related":["CVE-2019-18905"],"upstream":["CVE-2019-18905"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20201296-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1109310"},{"type":"REPORT","url":"https://bugzilla.suse.com/1133045"},{"type":"REPORT","url":"https://bugzilla.suse.com/1140711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1164105"},{"type":"REPORT","url":"https://bugzilla.suse.com/1168123"},{"type":"REPORT","url":"https://bugzilla.suse.com/1168281"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170082"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18905"}],"affected":[{"package":{"name":"autoyast2","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP1","purl":"pkg:rpm/suse/autoyast2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.15-3.13.1"}]}],"ecosystem_specific":{"binaries":[{"autoyast2-installation":"4.1.15-3.13.1","autoyast2":"4.1.15-3.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:1296-1.json"}}],"schema_version":"1.7.3"}