Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:104-2 Critical: suse/registry Vulnerability Resolution Notice

suse
Calendar Grey January 10, 2023
Dist Suse Esm H88
The container ubuntu/repository has been refreshed with crucial security fixes and advice. Ensure your safety by applying the recent updates.
The container suse/registry was updated

Summary

Advisory ID: SUSE-SU-2023:37-1 Released: Fri Jan 6 15:35:49 2023 Summary: Security update for ca-certificates-mozilla Type: security Severity: important Advisory ID: SUSE-RU-2023:48-1 Released: Mon Jan 9 10:37:54 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate Advisory ID: SUSE-RU-2023:50-1 Released: Mon Jan 9 10:42:21 2023 Summary: Recommended update for shadow

References

References : 1199467 1205502 1206212 1206622

1206212,1206622

This update for ca-certificates-mozilla fixes the following issues:

- Updated to 2.60 state of Mozilla SSL root CAs (bsc#1206622)

Removed CAs:

- Global Chambersign Root

- EC-ACC

- Network Solutions Certificate Authority

- Staat der Nederlanden EV Root CA

- SwissSign Platinum CA - G2

Added CAs:

- DIGITALSIGN GLOBAL ROOT ECDSA CA

- DIGITALSIGN GLOBAL ROOT RSA CA

- Security Communication ECC RootCA1

- Security Communication RootCA3

Changed trust:

- TrustCor certificates only trusted up to Nov 30 (bsc#1206212)

- Removed CAs (bsc#1206212) as most code does not handle 'valid before nov 30 2022'

and it is not clear how many certs were issued for SSL middleware by TrustCor:

- TrustCor RootCert CA-1

- TrustCor RootCert CA-2

- TrustCor ECA-1

1199467

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:103-1
Container Tags : suse/registry:2.8 , suse/registry:2.8-4.7 , suse/registry:latest
Container Release : 4.7
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here