Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: 2022:1001-1 Important: bci/nodejs Security Fix for Curl and Pam

suse
Calendar Grey May 14, 2022
Dist Suse Esm H88
Enhancements in the bci/nodejs container incorporate crucial security improvements for wget and ssh, resolving several vulnerabilities.
The container bci/nodejs was updated

Summary

Advisory ID: SUSE-RU-2022:1655-1 Released: Fri May 13 15:36:10 2022 Summary: Recommended update for pam Type: recommended Severity: moderate Advisory ID: SUSE-SU-2022:1657-1 Released: Fri May 13 15:39:07 2022 Summary: Security update for curl Type: security Severity: moderate Advisory ID: SUSE-RU-2022:1658-1 Released: Fri May 13 15:40:20 2022 Summary: Recommended update for libpsl Type: recommended

References

References : 1197771 1197794 1198614 1198723 1198766 CVE-2022-22576 CVE-2022-27775

CVE-2022-27776

1197794

This update for pam fixes the following issue:

- Do not include obsolete header files (bsc#1197794)

1198614,1198723,1198766,CVE-2022-22576,CVE-2022-27775,CVE-2022-27776

This update for curl fixes the following issues:

- CVE-2022-27776: Fixed auth/cookie leak on redirect (bsc#1198766)

- CVE-2022-27775: Fixed bad local IPv6 connection reuse (bsc#1198723)

- CVE-2022-22576: Fixed OAUTH2 bearer bypass in connection re-use (bsc#1198614)

1197771

This update for libpsl fixes the following issues:

- Fix libpsl compilation issues (bsc#1197771)

The following package changes have been done:

- libcurl4-7.66.0-150200.4.30.1 updated

- libpsl5-0.20.1-150000.3.3.1 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:1001-1
Container Tags : bci/node:14 , bci/node:14-19.16 , bci/nodejs:14 , bci/nodejs:14-19.16
Container Release : 19.16
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here