Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Warning: Undefined variable $read_more_description in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 1551

SUSE: 2022:2720-1 Important: Nodejs Container Security Issues

suse
Calendar Grey October 26, 2022
Dist Suse Esm H88
Urgent container notice for bci/nodejs with significant updates for libxml2 rectifying a range of security vulnerabilities.
The container bci/nodejs was updated

Summary

Advisory ID: SUSE-RU-2022:2796-1 Released: Fri Aug 12 14:34:31 2022 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate Advisory ID: SUSE-RU-2022:3328-1 Released: Wed Sep 21 12:48:56 2022 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate Advisory ID: SUSE-RU-2022:3551-1 Released: Fri Oct 7 17:03:55 2022

References

References : 1121365 1180995 1182983 1190651 1190653 1190700 1190888 1191020

1193859 1198471 1198472 1199492 1201293 1202117 1202148 1202870

1203046 1203069 1204366 1204367 CVE-2022-40303 CVE-2022-40304

This update for jitterentropy fixes the following issues:

jitterentropy is included in version 3.4.0 (jsc#SLE-24941):

This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library,

used by other FIPS libraries.

1202870

This update for jitterentropy fixes the following issues:

- Hide the non-GNUC constructs that are library internal from the

exported header, to make it usable in builds with strict C99

compliance. (bsc#1202870)

1182983,1190700,1191020,1202117

This update for libgcrypt fixes the following issues:

- FIPS: Fixed gpg/gpg2 gets out of core handler in FIPS mode while

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:2720-1
Container Tags : bci/node:14 , bci/node:14-35.6 , bci/nodejs:14 , bci/nodejs:14-35.6
Container Release : 35.6
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here