Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2023:2860-1 Moderate: Toolbox Security Fixes and Updates

suse
Calendar Grey September 6, 2023
Dist Suse Esm H88
SUSE Container Enhancement Notice for toolbox addresses critical security updates alongside numerous remedies for identified vulnerabilities.
The container suse/sle-micro/5.4/toolbox was updated

Summary

Advisory ID: SUSE-SU-2023:3397-1 Released: Wed Aug 23 18:35:56 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate Advisory ID: SUSE-RU-2023:3410-1 Released: Thu Aug 24 06:56:32 2023 Summary: Recommended update for audit Type: recommended Severity: moderate Advisory ID: SUSE-SU-2023:3440-1 Released: Mon Aug 28 08:57:10 2023 Summary: Security update for gawk

References

References : 1103893 1112183 1158763 1186606 1194609 1201519 1204844 1208194

1209741 1210702 1210740 1211576 1212434 1213185 1213231 1213517

1213557 1213575 1213673 1213853 1213873 1214025 1214071 1214290

CVE-2023-3817 CVE-2023-4016 CVE-2023-4156

1213517,1213853,CVE-2023-3817

This update for openssl-1_1 fixes the following issues:

- CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853)

- Don't pass zero length input to EVP_Cipher because s390x assembler optimized AES cannot handle zero size. (bsc#1213517)

1201519,1204844

This update for audit fixes the following issues:

- Create symbolic link from /sbin/audisp-syslog to /usr/sbin/audisp-syslog (bsc#1201519)

- Fix rules not loaded when restarting auditd.service (bsc#1204844)

Container Advisory ID : SUSE-CU-2023:2860-1
Container Tags : suse/sle-micro/5.4/toolbox:12.1 , suse/sle-micro/5.4/toolbox:12.1-4.2.98 , suse/sle-micro/5.4/toolbox:latest
Container Release : 4.2.98
Severity : moderate
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here