SUSE: 2023:3512-1 suse/nginx Security Update
Summary
Advisory ID: SUSE-RU-2023:4105-1 Released: Wed Oct 18 08:15:40 2023 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate Advisory ID: SUSE-SU-2023:4110-1 Released: Wed Oct 18 12:35:26 2023 Summary: Security update for glibc Type: security Severity: important Advisory ID: SUSE-RU-2023:4153-1 Released: Fri Oct 20 19:27:58 2023 Summary: Recommended update for systemd Type: recommended Severity: moderate Advisory ID: SUSE-RU-2023:4154-1 Released: Fri Oct 20 19:33:25 2023 Summary: Recommended update for aaa_base Type: recommended Severity: moderate
References
References : 1107342 1215215 1215286 1215313 1215434 1215891 CVE-2023-4813
1215215
This update for openssl-1_1 fixes the following issues:
- Displays 'fips' in the version string (bsc#1215215)
1215286,1215891,CVE-2023-4813
This update for glibc fixes the following issues:
Security issue fixed:
- CVE-2023-4813: Fixed a potential use-after-free in gaih_inet() (bsc#1215286, BZ #28931)
Also a regression from a previous update was fixed:
- elf: Align argument of __munmap to page size (bsc#1215891, BZ #28676)
1215313
This update for systemd fixes the following issues:
- Fix mismatch of nss-resolve version in Package Hub (no source code changes)
1107342,1215434
This update for aaa_base fixes the following issues:
- Respect /etc/update-alternatives/java when setting JAVA_HOME (bsc#1215434,bsc#1107342)
The following package changes have been done:
- glibc-2.31-150300.63.1 updated
- libsystemd0-249.16-150400.8.35.5 updated
- libopenssl1_1-1.1.1l-150500.17.19.1 updated
- libopenssl1_1-hmac-1.1.1l-150500.17.19.1 updated
- aaa_base-84.87+git20180409.04c9dae-150300.10.6.2 updated
- container:sles15-image-15.0.0-36.5.46 updated