{"id":"SUSE-SU-2022:3172-1","summary":"Security update for SUSE Manager Salt Bundle","details":"This update fixes the following issues:\n\nvenv-salt-minion:\n\n- Add support for gpgautoimport in zypperpkg module\n- Update Salt to work with Jinja \u003e= and \u003c= 3.1.0 (bsc#1198744)\n- Fix salt.states.file.managed() for follow_symlinks=True and test=True (bsc#1199372)\n- Make Salt 3004 compatible with pyzmq \u003e= 23.0.0 (bsc#1201082)\n- Add support for name, pkgs and diff_attr parameters to upgrade\n  function for zypper and yum (bsc#1198489)\n- Fix possible errors on running post install script\n  if semanage is present on the system, but SELinux is not configured\n- Remove unused imports in the venv wrappers\n- Set VENV_PIP_TARGET to /var/lib/venv-salt-minion/local\n  to force PIP use it as the destination to install modules\n- Fix ownership of salt thin directory when using the Salt Bundle\n- Set default target for pip from VENV_PIP_TARGET environment variable\n- Normalize package names once with pkg.installed/removed using yum (bsc#1195895)\n- Save log to logfile with docker.build\n- Use Salt Bundle in dockermod\n- Ignore errors on reading license files with dpkg_lowpkg (bsc#1197288)\n- Fix PAM auth issue due missing check for PAM_ACCT_MGM return value (CVE-2022-22967) (bsc#1200566)\n\n","modified":"2026-02-04T03:10:04.397358Z","published":"2022-09-08T07:29:45Z","related":["CVE-2022-22967"],"upstream":["CVE-2022-22967"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223172-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195895"},{"type":"REPORT","url":"https://bugzilla.suse.com/1197288"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198489"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198744"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199372"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200566"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201082"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-22967"}],"affected":[{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Client Tools 15","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3004-150000.3.11.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3004-150000.3.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3172-1.json"}},{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Proxy Module 4.3","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Proxy%20Module%204.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3004-150000.3.11.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3004-150000.3.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3172-1.json"}},{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Server Module 4.3","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Server%20Module%204.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3004-150000.3.11.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3004-150000.3.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3172-1.json"}}],"schema_version":"1.7.3"}