SUSE Container Update Advisory: suse/nginx
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:3695-1
Container Tags        : suse/nginx:1.21 , suse/nginx:1.21-5.29 , suse/nginx:latest
Container Release     : 5.29
Severity              : moderate
Type                  : security
References            : 1212535 1212881 1212883 1212888 1213273 1213274 1213589 1213590
                        1214574 CVE-2020-18768 CVE-2023-25433 CVE-2023-26966 CVE-2023-2908
                        CVE-2023-3316 CVE-2023-3576 CVE-2023-3618 CVE-2023-38288 CVE-2023-38289
-----------------------------------------------------------------

The container suse/nginx was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:4370-1
Released:    Mon Nov  6 09:51:10 2023
Summary:     Security update for tiff
Type:        security
Severity:    moderate
References:  1212535,1212881,1212883,1212888,1213273,1213274,1213589,1213590,1214574,CVE-2020-18768,CVE-2023-25433,CVE-2023-26966,CVE-2023-2908,CVE-2023-3316,CVE-2023-3576,CVE-2023-3618,CVE-2023-38288,CVE-2023-38289
This update for tiff fixes the following issues:

- CVE-2023-38289: Fixed a NULL pointer dereference in raw2tiff
  (bsc#1213589).
- CVE-2023-38288: Fixed an integer overflow in raw2tiff (bsc#1213590).
- CVE-2023-3576: Fixed a memory leak in tiffcrop (bsc#1213273).
- CVE-2020-18768: Fixed an out of bounds read in tiffcp (bsc#1214574).
- CVE-2023-26966: Fixed an out of bounds read when transforming a
  little-endian file to a big-endian output (bsc#1212881)
- CVE-2023-3618: Fixed a NULL pointer dereference while encoding FAX3
  files (bsc#1213274).
- CVE-2023-2908: Fixed an undefined behavior issue when doing pointer
  arithmetic on a NULL pointer (bsc#1212888).
- CVE-2023-3316: Fixed a NULL pointer dereference while opening a file
  in an inaccessible path (bsc#1212535).
- CVE-2023-25433: Fixed a buffer overflow in tiffcrop (bsc#1212883).


The following package changes have been done:

- libtiff5-4.0.9-150000.45.32.1 updated

SUSE: 2023:3695-1 suse/nginx Security Update

November 7, 2023
The container suse/nginx was updated

Summary

Advisory ID: SUSE-SU-2023:4370-1 Released: Mon Nov 6 09:51:10 2023 Summary: Security update for tiff Type: security Severity: moderate

References

References : 1212535 1212881 1212883 1212888 1213273 1213274 1213589 1213590

1214574 CVE-2020-18768 CVE-2023-25433 CVE-2023-26966 CVE-2023-2908

CVE-2023-3316 CVE-2023-3576 CVE-2023-3618 CVE-2023-38288 CVE-2023-38289

1212535,1212881,1212883,1212888,1213273,1213274,1213589,1213590,1214574,CVE-2020-18768,CVE-2023-25433,CVE-2023-26966,CVE-2023-2908,CVE-2023-3316,CVE-2023-3576,CVE-2023-3618,CVE-2023-38288,CVE-2023-38289

This update for tiff fixes the following issues:

- CVE-2023-38289: Fixed a NULL pointer dereference in raw2tiff

(bsc#1213589).

- CVE-2023-38288: Fixed an integer overflow in raw2tiff (bsc#1213590).

- CVE-2023-3576: Fixed a memory leak in tiffcrop (bsc#1213273).

- CVE-2020-18768: Fixed an out of bounds read in tiffcp (bsc#1214574).

- CVE-2023-26966: Fixed an out of bounds read when transforming a

little-endian file to a big-endian output (bsc#1212881)

- CVE-2023-3618: Fixed a NULL pointer dereference while encoding FAX3

files (bsc#1213274).

- CVE-2023-2908: Fixed an undefined behavior issue when doing pointer

arithmetic on a NULL pointer (bsc#1212888).

- CVE-2023-3316: Fixed a NULL pointer dereference while opening a file

in an inaccessible path (bsc#1212535).

- CVE-2023-25433: Fixed a buffer overflow in tiffcrop (bsc#1212883).

The following package changes have been done:

- libtiff5-4.0.9-150000.45.32.1 updated

Severity
Container Advisory ID : SUSE-CU-2023:3695-1
Container Tags : suse/nginx:1.21 , suse/nginx:1.21-5.29 , suse/nginx:latest
Container Release : 5.29
Severity : moderate
Type : security

Related News