Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2023:873-1 Moderate: Toolbox Security Update for Sudo

suse
Calendar Grey March 31, 2023
Dist Suse Esm H88
SUSE Container security enhancement introduces vital updates for toolbox and sudo, rectifying vulnerabilities related to control character management.
The container suse/sle-micro/5.4/toolbox was updated

Summary

Advisory ID: SUSE-RU-2023:1636-1 Released: Tue Mar 28 13:26:02 2023 Summary: Recommended update for suse-module-tools Type: recommended Severity: moderate Advisory ID: SUSE-SU-2023:1665-1 Released: Wed Mar 29 12:55:13 2023 Summary: Security update for sudo Type: security Severity: moderate

References

References : 1203201 1206483 1206772 1207853 1208595 1209361 1209362 CVE-2023-27320

CVE-2023-28486 CVE-2023-28487

1207853

This update for suse-module-tools fixes the following issues:

- Update to version 15.4.16:

* modprobe.conf: s390x: remove softdep on fbcon (bsc#1207853)

1203201,1206483,1206772,1208595,1209361,1209362,CVE-2023-27320,CVE-2023-28486,CVE-2023-28487

This update for sudo fixes the following issue:

Security issues:

- CVE-2023-28486: Fixed sudo does not escape control characters in log messages. (bsc#1209362)

- CVE-2023-28487: Fixed sudo does not escape control characters in sudoreplay output. (bsc#1209361)

- CVE-2023-27320: Fixed a potential security issue with a double free with per-command chroot sudoers rules (bsc#1208595).

Bug fixes:

Container Advisory ID : SUSE-CU-2023:873-1
Container Tags : suse/sle-micro/5.4/toolbox:12.1 , suse/sle-micro/5.4/toolbox:12.1-3.2.83 , suse/sle-micro/5.4/toolbox:latest
Container Release : 3.2.83
Severity : moderate
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here