The container suse/nginx was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/nginx ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2776-1 Container Tags : suse/nginx:1.21 , suse/nginx:1.21-3.19 , suse/nginx:latest Container Release : 3.19 Severity : moderate Type : security References : 1186606 1194609 1201519 1204844 1208194 1209741 1210419 1210702 1211576 1212434 1213185 1213575 1213873 1214025 CVE-2023-2004 CVE-2023-4156 ----------------------------------------------------------------- The container suse/nginx was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3410-1 Released: Thu Aug 24 06:56:32 2023 Summary: Recommended update for audit Type: recommended Severity: moderate References: 1201519,1204844 This update for audit fixes the following issues: - Create symbolic link from /sbin/audisp-syslog to /usr/sbin/audisp-syslog (bsc#1201519) - Fix rules not loaded when restarting auditd.service (bsc#1204844) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3440-1 Released: Mon Aug 28 08:57:10 2023 Summary: Security update for gawk Type: security Severity: low References: 1214025,CVE-2023-4156 This update for gawk fixes the following issues: - CVE-2023-4156: Fix a heap out of bound read by validating the index into argument list. (bsc#1214025) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3451-1 Released: Mon Aug 28 12:15:22 2023 Summary: Recommended update for systemd Type: recommended Severity: moderate References: 1186606,1194609,1208194,1209741,1210702,1211576,1212434,1213185,1213575,1213873 This update for systemd fixes the followingissues: - Fix reboot and shutdown issues by getting only active MD arrays (bsc#1211576, bsc#1212434, bsc#1213575) - Decrease devlink priority for iso disks (bsc#1213185) - Do not ignore mount point paths longer than 255 characters (bsc#1208194) - Refuse hibernation if there's no possible way to resume (bsc#1186606) - Update 'korean' and 'arabic' keyboard layouts (bsc#1210702) - Drop some entries no longer needed by YaST (bsc#1194609) - The 'systemd --user' instances get their own session keyring instead of the user default one (bsc#1209741) - Dynamically allocate receive buffer to handle large amount of mounts (bsc#1213873) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3461-1 Released: Mon Aug 28 17:25:09 2023 Summary: Security update for freetype2 Type: security Severity: moderate References: 1210419,CVE-2023-2004 This update for freetype2 fixes the following issues: - CVE-2023-2004: Fixed integer overflow in tt_hvadvance_adjust (bsc#1210419). The following package changes have been done: - libaudit1-3.0.6-150400.4.13.1 updated - libsystemd0-249.16-150400.8.33.1 updated - libfreetype6-2.10.4-150000.4.15.1 updated - gawk-4.2.1-150000.3.3.1 updated - container:sles15-image-15.0.0-36.5.28 updated . SUSE has launched a security patch for the suse/nginx container, tackling significant vulnerabilities and enhancing overall system performance.. SUSE Container Update, suse/nginx, security update, audit fix, freetype2 application. . LinuxSecurity.com Team
An update that solves one vulnerability and has three fixes is now available. . SUSE Security Update: Security update for audit ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1166-1 Rating: moderate References: #1042781 #1085003 #1125535 #941922 Cross-References: CVE-2015-5186 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Desktop 12-SP3 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for audit fixes the following issues: Audit on SUSE Linux Enterprise 12 SP3 was updated to 2.8.1 to bring new features and bugfixes. (bsc#1125535 FATE#326346) * Many features were added to auparse_normalize * cli option added to auditd and audispd for setting config dir * In auditd, restore the umask after creating a log file * Option added to auditd for skipping email verification The full changelog can be found here: https://people.redhat.com/sgrubb/audit/ChangeLog - Change openldap dependency to client only (bsc#1085003) Minor security issue fixed: - CVE-2015-5186: Audit: log terminal emulator escape sequences handling (bsc#941922) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-1166=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-1166=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-1166=1 Package List: - SUSE LinuxEnterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): audit-debugsource-2.8.1-8.3.1 audit-devel-2.8.1-8.3.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): audit-2.8.1-8.3.3 audit-audispd-plugins-2.8.1-8.3.3 audit-debugsource-2.8.1-8.3.1 libaudit1-2.8.1-8.3.1 libaudit1-debuginfo-2.8.1-8.3.1 libauparse0-2.8.1-8.3.1 libauparse0-debuginfo-2.8.1-8.3.1 - SUSE Linux Enterprise Server 12-SP3 (s390x x86_64): libaudit1-32bit-2.8.1-8.3.1 libaudit1-debuginfo-32bit-2.8.1-8.3.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): audit-2.8.1-8.3.3 audit-debugsource-2.8.1-8.3.1 libaudit1-2.8.1-8.3.1 libaudit1-32bit-2.8.1-8.3.1 libaudit1-debuginfo-2.8.1-8.3.1 libaudit1-debuginfo-32bit-2.8.1-8.3.1 libauparse0-2.8.1-8.3.1 libauparse0-debuginfo-2.8.1-8.3.1 References: https://www.suse.com/security/cve/CVE-2015-5186.html https://bugzilla.suse.com/1042781 https://bugzilla.suse.com/1085003 https://bugzilla.suse.com/1125535 https://bugzilla.suse.com/941922 _______________________________________________ sle-security-updates mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-438 2005-06-17 ---------------------------------------------------------------------Product : Fedora Core 4 Name : kdebase Version : 3.4.1 Release : 0.fc4.1 Summary : K Desktop Environment - core files Description : Core applications for the K Desktop Environment. Included are: kdm (replacement for xdm), kwin (window manager), konqueror (filemanager, web browser, ftp client, ...), konsole (xterm replacement), kpanel (application starter and desktop pager), kaudio (audio server), kdehelp (viewer for kde help files, info and man pages), kthememgr (system for managing alternate theme packages) plus other KDE components (kcheckpass, kikbd, kscreensaver, kcontrol, kfind, kfontmanager, kmenuedit). ---------------------------------------------------------------------* Mon Jun 13 2005 Than Ngo 3.4.1-0.fc4.1 - 3.4.1 - update pam configuration for the new audit system #159333 * Tue May 3 2005 Than Ngo 6:3.4.0-7 - fix broken kde-essential.menu * Tue Apr 19 2005 Than Ngo 6:3.4.0-6 - apply kdebase-3.4.0rc1-konsole-keymap.patch to change backspace key to ASCII-DEL, thanks to
Get the latest Linux and open source security news straight to your inbox.