Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:3803-1 Important Update: OpenSSL Denial of Service

suse
Calendar Grey November 22, 2023
Dist Suse Esm H88
Important notice for SUSE image suse/sle15 features security patches and mitigates denial of service vulnerabilities in OpenSSL.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2023:4511-1 Released: Tue Nov 21 16:43:08 2023 Summary: Security update for container-suseconnect Type: security Severity: important Advisory ID: SUSE-SU-2023:4519-1 Released: Tue Nov 21 17:39:58 2023 Summary: Security update for openssl-1_1 Type: security Severity: important

References

References : 1212475 1216922 CVE-2023-5678

1212475

This update of container-suseconnect fixes the following issues:

- rebuild the package with the go 1.21 security release (bsc#1212475).

1216922,CVE-2023-5678

This update for openssl-1_1 fixes the following issues:

- CVE-2023-5678: Fixed generating and checking of excessively long X9.42 DH keys that resulted in a possible Denial of Service (bsc#1216922).

The following package changes have been done:

- container-suseconnect-2.4.0-150000.4.44.1 updated

- libopenssl1_1-hmac-1.1.1d-150200.11.82.1 updated

- libopenssl1_1-1.1.1d-150200.11.82.1 updated

- openssl-1_1-1.1.1d-150200.11.82.1 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:3803-1
Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.215 , suse/sle15:15.3 , suse/sle15:15.3.17.20.215
Container Release : 17.20.215
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here