Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2023:2518-1 Important: Proxy TFTP Service Security Update

suse
Calendar Grey August 3, 2023
Dist Suse Esm H88
SUSE Container Update Notice for suse/manager/4.3/proxy-tftpd contains crucial security patches and suggested enhancements.
The container suse/manager/4.3/proxy-tftpd was updated

Summary

Advisory ID: SUSE-RU-2023:2625-1 Released: Fri Jun 23 17:16:11 2023 Summary: Recommended update for gcc12 Type: recommended Severity: moderate Advisory ID: SUSE-SU-2023:2648-1 Released: Tue Jun 27 09:52:35 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate Advisory ID: SUSE-SU-2023:2765-1 Released: Mon Jul 3 20:28:14 2023 Summary: Security update for libcap

References

References : 1201627 1207534 1208721 1209229 1210004 1210999 1211418 1211419

1211674 1211828 1212260 1212623 1213237 1213487 CVE-2022-4304

CVE-2023-2602 CVE-2023-2603 CVE-2023-31484 CVE-2023-32001 CVE-2023-32681

CVE-2023-3446

This update for gcc12 fixes the following issues:

- Update to GCC 12.3 release, 0c61aa720e62f1baf0bfd178e283, git1204

* includes regression and other bug fixes

- Speed up builds with --enable-link-serialization.

- Update embedded newlib to version 4.2.0

1201627,1207534,CVE-2022-4304

This update for openssl-1_1 fixes the following issues:

- CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption.

The previous fix for this timing side channel turned out to cause a

severe 2-3x performance regression in the typical use case (bsc#1207534).

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:2518-1
Container Tags : suse/manager/4.3/proxy-tftpd:4.3.7 , suse/manager/4.3/proxy-tftpd:4.3.7.9.24.1 , suse/manager/4.3/proxy-tftpd:latest , suse/manager/4.3/proxy-tftpd:susemanager-4.3.7 , suse/manager/4.3/proxy-tftpd:susemanager-4.3.7.9.24.1
Container Release : 9.24.1
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here