Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:141-1 Moderate: libksba Integer Overflow Security Update

suse
Calendar Grey January 11, 2023
Dist Suse Esm H88
An essential security enhancement for the SUSE Container suse/sle15 incorporates critical fixes addressing multiple packages and identified security weaknesses.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-RU-2023:45-1 Released: Mon Jan 9 10:32:26 2023 Summary: Recommended update for libxml2 Type: recommended Severity: moderate Advisory ID: SUSE-RU-2023:48-1 Released: Mon Jan 9 10:37:54 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate Advisory ID: SUSE-RU-2023:50-1 Released: Mon Jan 9 10:42:21 2023 Summary: Recommended update for shadow Type: recommended

References

References : 1199467 1204585 1205502 1206579 CVE-2022-47629

1204585

This update for libxml2 fixes the following issues:

- Add W3C conformance tests to the testsuite (bsc#1204585):

* Added file xmlts20080827.tar.gz

1199467

This update for libtirpc fixes the following issues:

- Consider /proc/sys/net/ipv4/ip_local_reserved_ports, before binding to a random port (bsc#1199467)

1205502

This update for shadow fixes the following issues:

- Fix issue with user id field that cannot be interpreted (bsc#1205502)

1206579,CVE-2022-47629

This update for libksba fixes the following issues:

- CVE-2022-47629: Fixed an integer overflow vulnerability in the CRL

signature parser (bsc#1206579).

The following package changes have been done:

- libksba8-1.3.5-150000.4.6.1 updated

Container Advisory ID : SUSE-CU-2023:141-1
Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.29 , suse/sle15:15.4 , suse/sle15:15.4.27.14.29
Container Release : 27.14.29
Severity : moderate
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here