Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:3318-1 Moderate: bci/bci-busybox Security Issue

suse
Calendar Grey December 9, 2022
Dist Suse Esm H88
SUSE Container Notification SUSE-CU-2022:3319-2 pertains to security enhancements for bci/bci-alpine, featuring patches and updated distributions.
The container bci/bci-busybox was updated

Summary

Advisory ID: SUSE-SU-2022:4371-1 Released: Thu Dec 8 17:19:43 2022 Summary: Security update for busybox Type: security Severity: moderate

References

References : 1199744 914660 CVE-2014-9645 CVE-2022-30065

1199744,914660,CVE-2014-9645,CVE-2022-30065

This update for busybox fixes the following issues:

- CVE-2022-30065: Fixed use-after-free in the AWK applet (bsc#1199744).

- CVE-2014-9645: Fixed loading of unwanted module with / in module names (bsc#914660).

- Update to 1.35.0 also introduced:

- awk: fix printf %%, fix read beyond end of buffer

- chrt: silence analyzer warning

- libarchive: remove duplicate forward declaration

- mount: 'mount -o rw ....' should not fall back to RO mount

- ps: fix -o pid=PID,args interpreting entire 'PID,args' as header

- tar: prevent malicious archives with long name sizes causing OOM

- udhcpc6: fix udhcp_find_option to actually find DHCP6 options

- xxd: fix -p -r

- support for new optoins added to basename, cpio, date, find,

Container Advisory ID : SUSE-CU-2022:3318-1
Container Tags : bci/bci-busybox:15.4 , bci/bci-busybox:15.4.13.3 , bci/bci-busybox:latest
Container Release : 13.3
Severity : moderate
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here