This update fixes the following issues: hub-xmlrpc-api: - Use golang(API) = 1.18 for building on SUSE (bsc#1203599) This source fails to build with the current go1.19 on SUSE and we need to use go1.18 instead. inter-server-sync: - Version 0.2.4 * Improve memory usage and log information #17193 * Conditional insert check for FK reference exists (bsc#1202785) * Correct navigation path for table rhnerratafilechannel (bsc#1202785) locale-formula: - Update to version 0.3 * Remove .map.gz from kb_map dictionary (bsc#1203406) py27-compat-salt: - Fix state.apply in test mode with file state module on user/group checking (bsc#1202167) - Make zypperpkg to retry if RPM lock is temporarily unavailable (bsc#1200596) python-urlgrabber: - Fix wrong logic on find_proxy method causing proxy not being used (bsc#1201788)
#1195624 #1197724 #1199726 #1200596 #1201059
#1201788 #1202167 #1202729 #1202785 #1203283
#1203406 #1203422 #1203564 #1203599 #1203611
#1203898 #1204146 #1204203 #1204543 #1204716
#1204741
Cross- CVE-2022-31255 CVE-2022-43753 CVE-2022-43754
CVSS scores:
CVE-2022-43753 (SUSE): 5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVE-2022-43754 (SUSE): 3 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
Affected Products:
SUSE Linux Enterprise Module for SUSE Manager Server 4.2
SUSE Manager Server 4.2
https://www.suse.com/security/cve/CVE-2022-31255.html
https://www.suse.com/security/cve/CVE-2022-43753.html
https://www.suse.com/security/cve/CVE-2022-43754.html
https://bugzilla.suse.com/1195624
https://bugzilla.suse.com/1197724
Get the latest Linux and open source security news straight to your inbox.