Description: SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and HTTP response splitting attacks, cause a DoS (Denial of Service), and potentially to compromise a user's system.
Note: A security issue in the resmgr package which causes it to grant access to all usb devices if access to one usb device was granted via the "usb:<bus>,<dev>" notation, has also been fixed.
Solution: Apply updated packages.
Updated packages are available using YaST Online Update or via the SUSE FTP site.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.