Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:2047-1 Moderate: Curl Denial Of Service Risk

suse
Calendar Grey September 7, 2022
Dist Suse Esm H88
The recent update incorporates security improvements for OpenSSL and coreutils, in addition to multiple enhancements for the ubuntu/bionic container.
The container suse/sles12sp5 was updated

Summary

Advisory ID: SUSE-RU-2022:2981-1 Released: Thu Sep 1 12:33:06 2022 Summary: Recommended update for util-linux Type: recommended Severity: moderate Advisory ID: SUSE-SU-2022:3005-1 Released: Fri Sep 2 15:02:47 2022 Summary: Security update for curl Type: security Severity: low Advisory ID: SUSE-RU-2022:3105-1 Released: Tue Sep 6 10:57:34 2022 Summary: Recommended update for keyutils Type: recommended

References

References : 1181994 1188006 1197178 1198731 1199079 1200842 1201929 1202593

1202868 CVE-2022-35252

1197178,1198731,1200842

This update for util-linux fixes the following issues:

- su: Change owner and mode for pty (bsc#1200842)

- agetty: Resolve tty name even if stdin is specified (bsc#1197178)

- libmount: When moving a mount point, update all sub mount entries in utab (bsc#1198731)

- mesg: use only stat() to get the current terminal status (bsc#1200842)

1202593,CVE-2022-35252

This update for curl fixes the following issues:

- CVE-2022-35252: Fixed a potential injection of control characters into cookies, which could be exploited by sister sites to cause a

denial of service (bsc#1202593).

1201929

This update for keyutils fixes the following issues:

Container Advisory ID : SUSE-CU-2022:2047-1
Container Tags : suse/sles12sp5:6.5.376 , suse/sles12sp5:latest
Container Release : 6.5.376
Severity : moderate
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here