Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

SUSE SLE15: 2023:4056-1 important: Curl and Build Key Patch

suse
Calendar Grey December 9, 2023
Dist Suse Esm H88
The Fedora Software Upgrade Alert delivers essential patches for curl and dnf, bolstering your system's integrity.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2023:4650-1 Released: Wed Dec 6 11:09:31 2023 Summary: Security update for curl Type: security Severity: moderate Advisory ID: SUSE-SU-2023:4672-1 Released: Wed Dec 6 14:37:37 2023 Summary: Security update for suse-build-key Type: security Severity: important

References

References : 1215889 1216410 1217215 1217573 CVE-2023-38546 CVE-2023-46218

1215889,1217573,CVE-2023-38546,CVE-2023-46218

This update for curl fixes the following issues:

- CVE-2023-38546: Fixed a cookie injection with none file (bsc#1215889).

- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).

1216410,1217215

This update for suse-build-key fixes the following issues:

This update runs a import-suse-build-key script.

The previous libzypp-post-script based installation is replaced

with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777).

- suse-build-key-import.service

- suse-build-key-import.timer

It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys.

After successful import the timer is disabled.

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:4056-1
Container Tags : suse/sle15:15.1 , suse/sle15:15.1.6.2.852
Container Release : 6.2.852
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here