Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE SLE15: 2023:3403-1 Important Curl and Shadow Fixes

suse
Calendar Grey October 13, 2023
Dist Suse Esm H88
Explore the newest insights in SUSE's container advisory which highlights critical patches and security enhancements for suse/sle15.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2023:4024-1 Released: Tue Oct 10 13:24:40 2023 Summary: Security update for shadow Type: security Severity: low Advisory ID: SUSE-SU-2023:4044-1 Released: Wed Oct 11 09:01:14 2023 Summary: Security update for curl Type: security Severity: important

References

References : 1214806 1215888 1215889 CVE-2023-38545 CVE-2023-38546 CVE-2023-4641

1214806,CVE-2023-4641

This update for shadow fixes the following issues:

- CVE-2023-4641: Fixed potential password leak (bsc#1214806).

1215888,1215889,CVE-2023-38545,CVE-2023-38546

This update for curl fixes the following issues:

- CVE-2023-38545: Fixed a heap buffer overflow in SOCKS5. (bsc#1215888)

- CVE-2023-38546: Fixed a cookie injection with none file. (bsc#1215889)

The following package changes have been done:

- curl-8.0.1-150400.5.32.1 updated

- libcurl4-8.0.1-150400.5.32.1 updated

- login_defs-4.8.1-150400.10.12.1 updated

- shadow-4.8.1-150400.10.12.1 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:3403-1
Container Tags : bci/bci-base:15.5 , bci/bci-base:15.5.36.5.42 , suse/sle15:15.5 , suse/sle15:15.5.36.5.42
Container Release : 36.5.42
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here