Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Linux Server 4.1 SUSE-SU-2022:3311-1 Moderate Tika-Core DoS

suse
Calendar Grey September 19, 2022
Dist Suse Esm H88
SUSE Security Update for libxml2 addresses critical flaws with guidelines for safe deployment practices.
An update that fixes three vulnerabilities is now available

Summary

This update for tika-core fixes the following issues: - CVE-2022-33879: Regular Expression Denial of Service in StandardsExtractingContentHandler (bsc#1201217) - CVE-2022-30973, CVE-2022-30126: Regular Expression Denial of Service in Standards Extractor (bsc#1199604, bsc#1200283) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.1-2022-3311=1 Package List: - SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (noarch): tika-core-1.26-150200.3.8.1

References

#1199604 #1200283 #1201217

Cross- CVE-2022-30126 CVE-2022-30973 CVE-2022-33879

CVSS scores:

CVE-2022-30126 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2022-30126 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-30973 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2022-30973 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-33879 (NVD) : 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CVE-2022-33879 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Module for SUSE Manager Server 4.1

SUSE Manager Server 4.1

https://www.suse.com/security/cve/CVE-2022-30126.html

https://www.suse.com/security/cve/CVE-2022-30973.html

Announcement ID: SUSE-SU-2022:3311-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here