SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2570-1 Container Tags : bci/rust:1.71 , bci/rust:1.71-1.10.8 , bci/rust:latest , bci/rust:stable , bci/rust:stable-1.10.8 Container Release : 10.8 Severity : important Type : security References : 1213817 1213853 CVE-2023-3817 CVE-2023-38497 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3242-1 Released: Tue Aug 8 18:19:40 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213853,CVE-2023-3817 This update for openssl-1_1 fixes the following issues: - CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3251-1 Released: Tue Aug 8 22:15:14 2023 Summary: Security update for rust1.71 Type: security Severity: important References: 1213817,CVE-2023-38497 This update for rust1.71 fixes the following issues: Update to version 1.71.1: - CVE-2023-38497: Fixed privilege escalation with Cargo not respecting umask when extracting dependencies (bsc#1213817). The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.15.1 updated - libopenssl1_1-hmac-1.1.1l-150500.17.15.1 updated - rust1.71-1.71.1-150400.9.6.1 updated - cargo1.71-1.71.1-150400.9.6.1 updated - container:sles15-image-15.0.0-36.5.22 updated