Advisory ID: SUSE-SU-2023:4650-1 Released: Wed Dec 6 11:09:31 2023 Summary: Security update for curl Type: security Severity: moderate Advisory ID: SUSE-SU-2023:4672-1 Released: Wed Dec 6 14:37:37 2023 Summary: Security update for suse-build-key Type: security Severity: important
References : 1215889 1216410 1217215 1217573 CVE-2023-38546 CVE-2023-46218
1215889,1217573,CVE-2023-38546,CVE-2023-46218
This update for curl fixes the following issues:
- CVE-2023-38546: Fixed a cookie injection with none file (bsc#1215889).
- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).
1216410,1217215
This update for suse-build-key fixes the following issues:
This update runs a import-suse-build-key script.
The previous libzypp-post-script based installation is replaced
with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777).
- suse-build-key-import.service
- suse-build-key-import.timer
It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys.
After successful import the timer is disabled.
Get the latest Linux and open source security news straight to your inbox.