Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2022:1628-1 Important: gpg2 Status Injection Risk

suse
Calendar Grey July 26, 2022
Dist Suse Esm H88
SUSE Container Patch Notice enhances gpg2 with vital corrections and significant updates addressing security flaws.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2022:2546-1 Released: Mon Jul 25 14:43:22 2022 Summary: Security update for gpg2 Type: security Severity: important

References

References : 1196125 1201225 CVE-2022-34903

1196125,1201225,CVE-2022-34903

This update for gpg2 fixes the following issues:

- CVE-2022-34903: Fixed a status injection vulnerability (bsc#1201225).

- Use AES as default cipher instead of 3DES when we are in FIPS mode. (bsc#1196125)

The following package changes have been done:

- gpg2-2.2.27-150300.3.5.1 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:1628-1
Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.5 , suse/sle15:15.3 , suse/sle15:15.3.17.20.5
Container Release : 17.20.5
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here