Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2023:776-1 Important: Container-SUSEConnect Security Update

suse
Calendar Grey March 23, 2023
Dist Suse Esm H88
SUSE Container Security Advisory: Provides essential patches for suse/sle15 container images targeting significant security flaws.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2023:871-1 Released: Wed Mar 22 14:32:45 2023 Summary: Security update for container-suseconnect Type: security Severity: important

References

References : 1200441 1206134 1208270 1208271 1208272 1209030 CVE-2022-41720

CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24532

1200441,1206134,1208270,1208271,1208272,1209030,CVE-2022-41720,CVE-2022-41723,CVE-2022-41724,CVE-2022-41725,CVE-2023-24532

This update of container-suseconnect fixes the following issue:

- container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7.

- CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270).

- CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271).

- CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272).

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:776-1
Container Tags : suse/sle15:15.1 , suse/sle15:15.1.6.2.748
Container Release : 6.2.748
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here