Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2024:4020-1 important: Salt Bundle Security Fixes

suse
Calendar Grey November 18, 2024
Dist Suse Esm H88
SUSE Manager Salt Package security enhancements revealed for critical flaws, strengthening overall system defense.
* bsc#1219041 * bsc#1220357 * bsc#1222842 * bsc#1226141 * bsc#1226447

Summary

## This update fixes the following issues: venv-salt-minion: * Security fixes on Python 3.11 interpreter: * CVE-2024-7592: Fixed quadratic complexity in parsing -quoted cookie values with backslashes (bsc#1229873, bsc#1230059) * CVE-2024-8088: Prevent malformed payload to cause infinite loops in zipfile.Path (bsc#1229704, bsc#1230058) * CVE-2024-6923: Prevent email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-4032: Rearranging definition of private global IP addresses (bsc#1226448) * CVE-2024-0397: ssl.SSLContext.cert_store_stats() and ssl.SSLContext.get_ca_certs() now correctly lock access to the certificate store, when the ssl.SSLContext is shared across multiple threads (bsc#1226447) * Security fixes on Python dependencies:

References

* bsc#1219041

* bsc#1220357

* bsc#1222842

* bsc#1226141

* bsc#1226447

* bsc#1226448

* bsc#1226469

* bsc#1227547

* bsc#1228105

* bsc#1228780

* bsc#1229109

* bsc#1229539

* bsc#1229654

* bsc#1229704

* bsc#1229873

* bsc#1229994

* bsc#1229995

* bsc#1229996

* bsc#1230058

* bsc#1230059

* bsc#1230322

* bsc#1231045

* bsc#1231697

* jsc#MSQA-863

Cross-

* CVE-2024-0397

* CVE-2024-3651

* CVE-2024-37891

* CVE-2024-4032

* CVE-2024-5569

* CVE-2024-6345

* CVE-2024-6923

* CVE-2024-7592

* CVE-2024-8088

CVSS scores:

* CVE-2024-0397 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

* CVE-2024-3651 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-3651 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:4020-1
Release Date: 2024-11-18T13:25:06Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here