Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:3563-3 Moderate: icu73_2 Security Flaws Resolved

suse
Calendar Grey October 30, 2023
Dist Suse Esm H88
Crucial patch released for icu73_2. Various citations noted and guidelines presented for SUSE upgrade.
* bsc#1030253 * bsc#1095425 * bsc#1103893 * bsc#1112183 * bsc#1146907

Summary

## This update for icu73_2 fixes the following issues: * Update to release 73.2 * CLDR extends the support for “short” Chinese sort orders to cover some additional, required characters for Level 2. This is carried over into ICU collation. * ICU has a modified character conversion table, mapping some GB18030 characters to Unicode characters that were encoded after GB18030-2005. * fixes builds where UCHAR_TYPE is re-defined such as libqt5-qtwebengine * Update to release 73.1 * Improved Japanese and Korean short-text line breaking * Reduction of C++ memory use in date formatting * Update to release 72.1 * Support for Unicode 15, including new characters, scripts, emoji, and corresponding API constants. * Support for CLDR 42 locale data with various additions and corrections.

References

* bsc#1030253

* bsc#1095425

* bsc#1103893

* bsc#1112183

* bsc#1146907

* bsc#1158955

* bsc#1159131

* bsc#1161007

* bsc#1162882

* bsc#1166844

* bsc#1167603

* bsc#1182252

* bsc#1182645

* bsc#1192935

* bsc#1193951

* bsc#354372

* bsc#437293

* bsc#824262

* jsc#PED-4917

* jsc#SLE-11118

Cross-

* CVE-2020-10531

* CVE-2020-21913

CVSS scores:

* CVE-2020-10531 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2020-10531 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2020-21913 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2020-21913 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP4

* Basesystem Module 15-SP5

* openSUSE Leap Micro 5.2

* openSUSE Leap Micro 5.3

* openSUSE Leap Micro 5.4

Announcement ID: SUSE-SU-2023:3563-3
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here