Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2023:4119-1 important: curl and suse-build-key security fix

suse
Calendar Grey December 13, 2023
Dist Suse Esm H88
SUSE Container Advisory with critical updates for curl and suse-build-key addressing potential exploitation risks.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2023:4659-1 Released: Wed Dec 6 13:04:57 2023 Summary: Security update for curl Type: security Severity: moderate Advisory ID: SUSE-RU-2023:4671-1 Released: Wed Dec 6 14:33:41 2023 Summary: Recommended update for man Type: recommended Severity: moderate Advisory ID: SUSE-SU-2023:4672-1 Released: Wed Dec 6 14:37:37 2023 Summary: Security update for suse-build-key Type: security

References

References : 1216410 1216862 1217212 1217215 1217573 1217574 CVE-2023-46218

CVE-2023-46219

1217573,1217574,CVE-2023-46218,CVE-2023-46219

This update for curl fixes the following issues:

- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).

- CVE-2023-46219: HSTS long file name clears contents (bsc#1217574).

This update of man fixes the following problem:

- The 'man' commands is delivered to SUSE Linux Enterprise Micro

to allow browsing man pages.

1216410,1217215

This update for suse-build-key fixes the following issues:

This update runs a import-suse-build-key script.

The previous libzypp-post-script based installation is replaced

with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777).

- suse-build-key-import.service

- suse-build-key-import.timer

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:4119-1
Container Tags : bci/bci-base:15.5 , bci/bci-base:15.5.36.5.63 , suse/sle15:15.5 , suse/sle15:15.5.36.5.63
Container Release : 36.5.63
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here