SUSE Container Update Advisory: suse/sles12sp5
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:3096-1
Container Tags        : suse/sles12sp5:6.5.513 , suse/sles12sp5:latest
Container Release     : 6.5.513
Severity              : important
Type                  : security
References            : 1201978 1210411 1210412 1214052 1214768 1215026 CVE-2016-3709
                        CVE-2023-28484 CVE-2023-29469 CVE-2023-38039 CVE-2023-39615 CVE-2023-4039
-----------------------------------------------------------------

The container suse/sles12sp5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3640-1
Released:    Mon Sep 18 13:58:28 2023
Summary:     Security update for gcc12
Type:        security
Severity:    important
References:  1214052,CVE-2023-4039
This update for gcc12 fixes the following issues:

- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3665-1
Released:    Mon Sep 18 21:51:22 2023
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1201978,1210411,1210412,1214768,CVE-2016-3709,CVE-2023-28484,CVE-2023-29469,CVE-2023-39615
This update for libxml2 fixes the following issues:

- CVE-2023-29469: Fixed not deterministic hashing of empty dict strings (bsc#1210412).
- CVE-2023-28484: Fixed NULL dereference in xmlSchemaFixupComplexType (bsc#1210411).
- CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768).
- CVE-2016-3709: Fixed cross-site scripting vulnerability in libxml (bsc#1201978).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3692-1
Released:    Tue Sep 19 22:05:52 2023
Summary:     Security update for curl
Type:        security
Severity:    important
References:  1215026,CVE-2023-38039
This update for curl fixes the following issues:

- CVE-2023-38039: Fixed possible DoS when receiving too large HTTP header. (bsc#1215026)


The following package changes have been done:

- libcurl4-8.0.1-11.71.1 updated
- libgcc_s1-12.3.0+git1204-1.13.1 updated
- libstdc++6-12.3.0+git1204-1.13.1 updated
- libxml2-2-2.9.4-46.65.1 updated

SUSE: 2023:3096-1 suse/sles12sp5 Security Update

September 24, 2023
The container suse/sles12sp5 was updated

Summary

Advisory ID: SUSE-SU-2023:3640-1 Released: Mon Sep 18 13:58:28 2023 Summary: Security update for gcc12 Type: security Severity: important Advisory ID: SUSE-SU-2023:3665-1 Released: Mon Sep 18 21:51:22 2023 Summary: Security update for libxml2 Type: security Severity: important Advisory ID: SUSE-SU-2023:3692-1 Released: Tue Sep 19 22:05:52 2023 Summary: Security update for curl Type: security Severity: important

References

References : 1201978 1210411 1210412 1214052 1214768 1215026 CVE-2016-3709

CVE-2023-28484 CVE-2023-29469 CVE-2023-38039 CVE-2023-39615 CVE-2023-4039

1214052,CVE-2023-4039

This update for gcc12 fixes the following issues:

- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).

1201978,1210411,1210412,1214768,CVE-2016-3709,CVE-2023-28484,CVE-2023-29469,CVE-2023-39615

This update for libxml2 fixes the following issues:

- CVE-2023-29469: Fixed not deterministic hashing of empty dict strings (bsc#1210412).

- CVE-2023-28484: Fixed NULL dereference in xmlSchemaFixupComplexType (bsc#1210411).

- CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768).

- CVE-2016-3709: Fixed cross-site scripting vulnerability in libxml (bsc#1201978).

1215026,CVE-2023-38039

This update for curl fixes the following issues:

- CVE-2023-38039: Fixed possible DoS when receiving too large HTTP header. (bsc#1215026)

The following package changes have been done:

- libcurl4-8.0.1-11.71.1 updated

- libgcc_s1-12.3.0+git1204-1.13.1 updated

- libstdc++6-12.3.0+git1204-1.13.1 updated

- libxml2-2-2.9.4-46.65.1 updated

Severity
Container Advisory ID : SUSE-CU-2023:3096-1
Container Tags : suse/sles12sp5:6.5.513 , suse/sles12sp5:latest
Container Release : 6.5.513
Severity : important
Type : security

Related News