SUSE Container Update Advisory: bci/openjdk-devel
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:2503-1
Container Tags        : bci/openjdk-devel:11 , bci/openjdk-devel:11-8.43
Container Release     : 8.43
Severity              : moderate
Type                  : security
References            : 1179926 1212401 1213517 CVE-2020-8908 CVE-2023-2976 
-----------------------------------------------------------------

The container bci/openjdk-devel was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3090-1
Released:    Tue Aug  1 10:24:13 2023
Summary:     Security update for guava
Type:        security
Severity:    moderate
References:  1179926,1212401,CVE-2020-8908,CVE-2023-2976
This update for guava fixes the following issues:

Upgrade to guava 32.0.1:

- CVE-2020-8908: Fixed predictable temporary files and directories used in FileBackedOutputStream (bsc#1179926).
- CVE-2023-2976: Fixed a temp directory creation vulnerability (bsc#1212401).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:3102-1
Released:    Tue Aug  1 14:11:53 2023
Summary:     Recommended update for openssl-1_1
Type:        recommended
Severity:    moderate
References:  1213517
This update for openssl-1_1 fixes the following issues:

- Dont pass zero length input to EVP_Cipher (bsc#1213517)


The following package changes have been done:

- libopenssl1_1-1.1.1l-150500.17.12.1 updated
- libopenssl1_1-hmac-1.1.1l-150500.17.12.1 updated
- openssl-1_1-1.1.1l-150500.17.12.1 updated
- guava-32.0.1-150200.3.7.1 updated
- container:bci-openjdk-11-15.5.11-9.21 updated

SUSE: 2023:2503-1 bci/openjdk-devel Security Update

August 2, 2023
The container bci/openjdk-devel was updated

Summary

Advisory ID: SUSE-SU-2023:3090-1 Released: Tue Aug 1 10:24:13 2023 Summary: Security update for guava Type: security Severity: moderate Advisory ID: SUSE-RU-2023:3102-1 Released: Tue Aug 1 14:11:53 2023 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate

References

References : 1179926 1212401 1213517 CVE-2020-8908 CVE-2023-2976

1179926,1212401,CVE-2020-8908,CVE-2023-2976

This update for guava fixes the following issues:

Upgrade to guava 32.0.1:

- CVE-2020-8908: Fixed predictable temporary files and directories used in FileBackedOutputStream (bsc#1179926).

- CVE-2023-2976: Fixed a temp directory creation vulnerability (bsc#1212401).

1213517

This update for openssl-1_1 fixes the following issues:

- Dont pass zero length input to EVP_Cipher (bsc#1213517)

The following package changes have been done:

- libopenssl1_1-1.1.1l-150500.17.12.1 updated

- libopenssl1_1-hmac-1.1.1l-150500.17.12.1 updated

- openssl-1_1-1.1.1l-150500.17.12.1 updated

- guava-32.0.1-150200.3.7.1 updated

- container:bci-openjdk-11-15.5.11-9.21 updated

Severity
Container Advisory ID : SUSE-CU-2023:2503-1
Container Tags : bci/openjdk-devel:11 , bci/openjdk-devel:11-8.43
Container Release : 8.43
Severity : moderate
Type : security

Related News