Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:3456-2 Critical: Remote Exploit in Server Applications

suse
Calendar Grey June 20, 2022
Dist Suse Esm H88
This essential Ubuntu Security Patch tackles severe vulnerabilities in Ubuntu Management Console, boosting resilience and safeguarding integrity.
An update that fixes 13 vulnerabilities, contains 5 features is now available

Summary

This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Adapted to build on Enterprise Linux. - Fix build for RedHat 7 - Require Go >= 1.14 also for CentOS - Add support for CentOS - Replace %{?systemd_requires} with %{?systemd_ordering} golang-github-prometheus-alertmanager: - CVE-2022-21698: Denial of service using InstrumentHandlerCounter. * Update vendor tarball with prometheus/client_golang 1.11.1 (bsc#1196338, jsc#SLE-24077) - Update required Go version to 1.16 - Update to version 0.23.0: * amtool: Detect version drift and warn users (#2672) * Add ability to skip TLS verification for amtool (#2663) * Fix empty isEqual in amtool. (#2668) * Fix main tests (#2670) * cli: add new template render command (#2538) * OpsGenie: refer to alert instead of incident (#2609)

References

#1181223 #1181400 #1190462 #1190535 #1193600

#1194873 #1195726 #1195727 #1195728 #1196338

#1196704 #1197507 #1197689 SLE-23422 SLE-23439

SLE-24077 SLE-24238 SLE-24239

Cross- CVE-2021-36222 CVE-2021-3711 CVE-2021-39226

CVE-2021-41174 CVE-2021-41244 CVE-2021-43798

CVE-2021-43813 CVE-2021-43815 CVE-2022-21673

CVE-2022-21698 CVE-2022-21702 CVE-2022-21703

CVE-2022-21713

CVSS scores:

CVE-2021-36222 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-36222 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-3711 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-3711 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-39226 (NVD) : 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2134-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here