DSA-2020-254: NetWorker vProxy Security Update for SLES Vulnerabilities

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Multiple components within NetWorker vProxy require a security update to address various vulnerabilities. 

Third-party Component  CVE(s) More information
SUSE SLES12 Security Update: kernel (SUSE-SU-2020:2121-1) CVE-2019-16746 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
CVE-2019-20810
CVE-2019-20908
CVE-2020-0305
CVE-2020-10766
CVE-2020-10767
CVE-2020-10768
CVE-2020-10769
CVE-2020-10773
CVE-2020-12771
CVE-2020-12888
CVE-2020-13974
CVE-2020-14416
CVE-2020-15393
CVE-2020-15780
SUSE SLES12 Security Update: xerces-c (SUSE-SU-2020:2225-1) CVE-2017-12627
SUSE SLES12 Security Update: libX11 (SUSE-SU-2020:2196-1) CVE-2020-14344
SUSE SLES12 Security Update: grub2 (SUSE-SU-2020:2305-1) CVE-2020-15705

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/.  

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
Third-party Component  CVE(s) More information
SUSE SLES12 Security Update: kernel (SUSE-SU-2020:2121-1) CVE-2019-16746 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
CVE-2019-20810
CVE-2019-20908
CVE-2020-0305
CVE-2020-10766
CVE-2020-10767
CVE-2020-10768
CVE-2020-10769
CVE-2020-10773
CVE-2020-12771
CVE-2020-12888
CVE-2020-13974
CVE-2020-14416
CVE-2020-15393
CVE-2020-15780
SUSE SLES12 Security Update: xerces-c (SUSE-SU-2020:2225-1) CVE-2017-12627
SUSE SLES12 Security Update: libX11 (SUSE-SU-2020:2196-1) CVE-2020-14344
SUSE SLES12 Security Update: grub2 (SUSE-SU-2020:2305-1) CVE-2020-15705

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/.  

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:    
NetWorker vProxy 4.2.0-5, 4.1.0-11, 4.0.0-15 and earlier versions


Remediation:     
The following NetWorker vProxy release addresses these vulnerabilities:    

  • NetWorker vProxy version 4.2.0-7

Dell recommends all customers upgrade at the earliest opportunity.



Affected products:    
NetWorker vProxy 4.2.0-5, 4.1.0-11, 4.0.0-15 and earlier versions


Remediation:     
The following NetWorker vProxy release addresses these vulnerabilities:    

  • NetWorker vProxy version 4.2.0-7

Dell recommends all customers upgrade at the earliest opportunity.



Related Information

Affected Products

NetWorker

Products

Backup and Recovery Manager NetWorker, NetWorker, NetWorker Series, NetWorker for OpenVMS, NetWorker Management Console, NetWorker Module, NetWorker Module for Databases and Applications, NetWorker Module for MEDITECH, NetWorker Module for Microsoft , NetWorker Module for SAP, Product Security Information, vRealize Data Protection Extension for NetWorker ...
Article Properties
Article Number: 000180926
Article Type: Dell Security Advisory
Last Modified: 22 May 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.