SUSE Container Update Advisory: suse/sle15
Container Advisory ID : SUSE-CU-2023:4056-1
Container Tags        : suse/sle15:15.1 , suse/sle15:
Container Release     : 6.2.852
Severity              : important
Type                  : security
References            : 1215889 1216410 1217215 1217573 CVE-2023-38546 CVE-2023-46218

The container suse/sle15 was updated. The following patches have been included in this update:

Advisory ID: SUSE-SU-2023:4650-1
Released:    Wed Dec  6 11:09:31 2023
Summary:     Security update for curl
Type:        security
Severity:    moderate
References:  1215889,1217573,CVE-2023-38546,CVE-2023-46218
This update for curl fixes the following issues:

- CVE-2023-38546: Fixed a cookie injection with none file (bsc#1215889).
- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).

Advisory ID: SUSE-SU-2023:4672-1
Released:    Wed Dec  6 14:37:37 2023
Summary:     Security update for suse-build-key
Type:        security
Severity:    important
References:  1216410,1217215
This update for suse-build-key fixes the following issues:

This update runs a import-suse-build-key script.

The previous libzypp-post-script based installation is replaced
with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777).
  - suse-build-key-import.service
  - suse-build-key-import.timer

It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys.
After successful import the timer is disabled.

To manually import them you can also run:

# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc
# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc

The following package changes have been done:

- libcurl4-7.60.0-150000.56.1 updated
- suse-build-key-12.0-150000.8.37.1 updated

SUSE: 2023:4056-1 suse/sle15 Security Update

December 9, 2023
The container suse/sle15 was updated


Advisory ID: SUSE-SU-2023:4650-1 Released: Wed Dec 6 11:09:31 2023 Summary: Security update for curl Type: security Severity: moderate Advisory ID: SUSE-SU-2023:4672-1 Released: Wed Dec 6 14:37:37 2023 Summary: Security update for suse-build-key Type: security Severity: important


References : 1215889 1216410 1217215 1217573 CVE-2023-38546 CVE-2023-46218


This update for curl fixes the following issues:

- CVE-2023-38546: Fixed a cookie injection with none file (bsc#1215889).

- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).


This update for suse-build-key fixes the following issues:

This update runs a import-suse-build-key script.

The previous libzypp-post-script based installation is replaced

with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777).

- suse-build-key-import.service

- suse-build-key-import.timer

It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys.

After successful import the timer is disabled.

To manually import them you can also run:

# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc

# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc

The following package changes have been done:

- libcurl4-7.60.0-150000.56.1 updated

- suse-build-key-12.0-150000.8.37.1 updated

Container Advisory ID : SUSE-CU-2023:4056-1
Container Tags : suse/sle15:15.1 , suse/sle15:
Container Release : 6.2.852
Severity : important
Type : security

Related News