Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2024:4294-1 moderate: socat update for arbitrary file overwrite

suse
Calendar Grey December 11, 2024
Dist Suse Esm H88
Important enhancement for socat addresses significant challenges. Adhere to setup guidelines for openSUSE platforms now.
* bsc#1225462 Cross-References: * CVE-2024-54661

Summary

## This update for socat fixes the following issues: * CVE-2024-54661: Fixed arbitrary file overwrite via predictable /tmp directory (bsc#1225462) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2024-4294=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * socat-debugsource-1.7.2.4-4.3.1 * socat-1.7.2.4-4.3.1 * socat-debuginfo-1.7.2.4-4.3.1

References

* bsc#1225462

Cross-

* CVE-2024-54661

CVSS scores:

* CVE-2024-54661 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-54661 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-54661.html

* https://bugzilla.suse.com/show_bug.cgi?id=1225462

Announcement ID: SUSE-SU-2024:4294-1
Release Date: 2024-12-11T13:06:43Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here