* bsc#1229163 * bsc#1229164 * bsc#1233606 * bsc#1233608 * bsc#1233609 . # Security update for grub2 Announcement ID: SUSE-SU-2025:0586-1 Release Date: 2025-02-19T07:29:02Z Rating: important References: * bsc#1229163 * bsc#1229164 * bsc#1233606 * bsc#1233608 * bsc#1233609 * bsc#1233610 * bsc#1233612 * bsc#1233613 * bsc#1233614 * bsc#1233615 * bsc#1233616 * bsc#1233617 * bsc#1234958 * bsc#1236316 * bsc#1236317 * bsc#1237002 * bsc#1237006 * bsc#1237008 * bsc#1237009 * bsc#1237010 * bsc#1237011 * bsc#1237012 * bsc#1237013 * bsc#1237014 Cross-References: * CVE-2024-45774 * CVE-2024-45775 * CVE-2024-45776 * CVE-2024-45777 * CVE-2024-45778 * CVE-2024-45779 * CVE-2024-45780 * CVE-2024-45781 * CVE-2024-45782 * CVE-2024-45783 * CVE-2024-49504 * CVE-2024-56737 * CVE-2025-0622 * CVE-2025-0624 * CVE-2025-0677 * CVE-2025-0678 * CVE-2025-0684 * CVE-2025-0685 * CVE-2025-0686 * CVE-2025-0689 * CVE-2025-0690 * CVE-2025-1118 * CVE-2025-1125 CVSS scores: * CVE-2024-45774 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45774 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45775 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45775 ( NVD ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2024-45776 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45776 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45777 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45778 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2024-45779 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45780 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45781 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45781 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45782 ( SUSE ): 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45783 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45783 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-49504 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-49504 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-49504 ( NVD ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-56737 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56737 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-56737 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-0622 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0622 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0624 ( SUSE ): 7.6 CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2025-0677 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0677 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0678 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0684 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0685 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0685 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0686 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0686 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0689 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0689 ( SUSE ): 6.4CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0690 ( SUSE ): 7.3 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0690 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1118 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-1118 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2025-1125 ( SUSE ): 8.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-1125 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 23 vulnerabilities and has one security fix can now be installed. ## Description: This update for grub2 fixes the following issues: * CVE-2024-45781: Fixed strcpy overflow in ufs. (bsc#1233617) * CVE-2024-56737: Fixed a heap-based buffer overflow in hfs. (bsc#1234958) * CVE-2024-45782: Fixed strcpy overflow in hfs. (bsc#1233615) * CVE-2024-45780: Fixed an overflow in tar/cpio. (bsc#1233614) * CVE-2024-45783: Fixed a refcount overflow in hfsplus. (bsc#1233616) * CVE-2024-45774: Fixed a heap overflow in JPEG parser. (bsc#1233609) * CVE-2024-45775: Fixed a missing NULL check in extcmd parser. (bsc#1233610) * CVE-2024-45776: Fixed an overflow in .MO file handling. (bsc#1233612) * CVE-2024-45777: Fixed an integer overflow in gettext. (bsc#1233613) * CVE-2024-45778: Fixed bfs filesystem by removing it from lockdown capable modules. (bsc#1233606) * CVE-2024-45779: Fixed a heap overflow in bfs. (bsc#1233608) * CVE-2024-49504: Fixed an issue that can bypass TPM-bound disk encryption on SL(E)M encrypted Images. (bsc#1229164) * CVE-2025-0624: Fixed an out-of-bounds write during the network bootprocess. (bsc#1236316) * CVE-2025-0622: Fixed a use-after-free when handling hooks during module unload in command/gpg . (bsc#1236317) * CVE-2025-0690: Fixed an integer overflow that may lead to an out-of-bounds write through the read command. (bsc#1237012) * CVE-2025-1118: Fixed an issue where the dump command was not being blocked when grub was in lockdown mode. (bsc#1237013) * CVE-2025-0677: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in ufs. (bsc#1237002) * CVE-2025-0684: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in reiserfs. (bsc#1237008) * CVE-2025-0685: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in jfs. (bsc#1237009) * CVE-2025-0686: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in romfs. (bsc#1237010) * CVE-2025-0689: Fixed a heap-based buffer overflow in udf that may lead to arbitrary code execution. (bsc#1237011) * CVE-2025-1125: Fixed an integer overflow that may lead to an out-of-bounds write in hfs. (bsc#1237014) * CVE-2025-0678: Fixed an integer overflow that may lead to an out-of-bounds write in squash4. (bsc#1237006) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-586=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-586=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-586=1 openSUSE-SLE-15.6-2025-586=1 ## Package List: * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * grub2-debuginfo-2.12-150600.8.18.2 * grub2-2.12-150600.8.18.2 * Basesystem Module 15-SP6 (noarch) *grub2-powerpc-ieee1275-2.12-150600.8.18.2 * grub2-systemd-sleep-plugin-2.12-150600.8.18.2 * grub2-x86_64-efi-2.12-150600.8.18.2 * grub2-snapper-plugin-2.12-150600.8.18.2 * grub2-i386-pc-2.12-150600.8.18.2 * grub2-arm64-efi-2.12-150600.8.18.2 * Basesystem Module 15-SP6 (aarch64 s390x x86_64) * grub2-debugsource-2.12-150600.8.18.2 * Basesystem Module 15-SP6 (s390x) * grub2-s390x-emu-2.12-150600.8.18.2 * Server Applications Module 15-SP6 (noarch) * grub2-x86_64-xen-2.12-150600.8.18.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * grub2-branding-upstream-2.12-150600.8.18.2 * grub2-debuginfo-2.12-150600.8.18.2 * grub2-2.12-150600.8.18.2 * openSUSE Leap 15.6 (aarch64 s390x x86_64 i586) * grub2-debugsource-2.12-150600.8.18.2 * openSUSE Leap 15.6 (noarch) * grub2-powerpc-ieee1275-2.12-150600.8.18.2 * grub2-x86_64-efi-extras-2.12-150600.8.18.2 * grub2-i386-pc-extras-2.12-150600.8.18.2 * grub2-x86_64-xen-debug-2.12-150600.8.18.2 * grub2-i386-efi-extras-2.12-150600.8.18.2 * grub2-arm64-efi-2.12-150600.8.18.2 * grub2-i386-pc-debug-2.12-150600.8.18.2 * grub2-x86_64-xen-2.12-150600.8.18.2 * grub2-i386-efi-debug-2.12-150600.8.18.2 * grub2-snapper-plugin-2.12-150600.8.18.2 * grub2-s390x-emu-extras-2.12-150600.8.18.2 * grub2-i386-xen-debug-2.12-150600.8.18.2 * grub2-powerpc-ieee1275-debug-2.12-150600.8.18.2 * grub2-systemd-sleep-plugin-2.12-150600.8.18.2 * grub2-i386-pc-2.12-150600.8.18.2 * grub2-arm64-efi-debug-2.12-150600.8.18.2 * grub2-i386-xen-2.12-150600.8.18.2 * grub2-arm64-efi-extras-2.12-150600.8.18.2 * grub2-x86_64-efi-debug-2.12-150600.8.18.2 * grub2-x86_64-xen-extras-2.12-150600.8.18.2 * grub2-powerpc-ieee1275-extras-2.12-150600.8.18.2 * grub2-x86_64-efi-2.12-150600.8.18.2 * grub2-i386-efi-2.12-150600.8.18.2 * grub2-i386-xen-extras-2.12-150600.8.18.2 * openSUSE Leap 15.6 (s390x) * grub2-s390x-emu-debug-2.12-150600.8.18.2 *grub2-s390x-emu-2.12-150600.8.18.2 ## References: * https://www.suse.com/security/cve/CVE-2024-45774.html * https://www.suse.com/security/cve/CVE-2024-45775.html * https://www.suse.com/security/cve/CVE-2024-45776.html * https://www.suse.com/security/cve/CVE-2024-45777.html * https://www.suse.com/security/cve/CVE-2024-45778.html * https://www.suse.com/security/cve/CVE-2024-45779.html * https://www.suse.com/security/cve/CVE-2024-45780.html * https://www.suse.com/security/cve/CVE-2024-45781.html * https://www.suse.com/security/cve/CVE-2024-45782.html * https://www.suse.com/security/cve/CVE-2024-45783.html * https://www.suse.com/security/cve/CVE-2024-49504.html * https://www.suse.com/security/cve/CVE-2024-56737.html * https://www.suse.com/security/cve/CVE-2025-0622.html * https://www.suse.com/security/cve/CVE-2025-0624.html * https://www.suse.com/security/cve/CVE-2025-0677.html * https://www.suse.com/security/cve/CVE-2025-0678.html * https://www.suse.com/security/cve/CVE-2025-0684.html * https://www.suse.com/security/cve/CVE-2025-0685.html * https://www.suse.com/security/cve/CVE-2025-0686.html * https://www.suse.com/security/cve/CVE-2025-0689.html * https://www.suse.com/security/cve/CVE-2025-0690.html * https://www.suse.com/security/cve/CVE-2025-1118.html * https://www.suse.com/security/cve/CVE-2025-1125.html * https://bugzilla.suse.com/show_bug.cgi?id=1229163 * https://bugzilla.suse.com/show_bug.cgi?id=1229164 * https://bugzilla.suse.com/show_bug.cgi?id=1233606 * https://bugzilla.suse.com/show_bug.cgi?id=1233608 * https://bugzilla.suse.com/show_bug.cgi?id=1233609 * https://bugzilla.suse.com/show_bug.cgi?id=1233610 * https://bugzilla.suse.com/show_bug.cgi?id=1233612 * https://bugzilla.suse.com/show_bug.cgi?id=1233613 * https://bugzilla.suse.com/show_bug.cgi?id=1233614 * https://bugzilla.suse.com/show_bug.cgi?id=1233615 * https://bugzilla.suse.com/show_bug.cgi?id=1233616 * https://bugzilla.suse.com/show_bug.cgi?id=1233617 *https://bugzilla.suse.com/show_bug.cgi?id=1234958 * https://bugzilla.suse.com/show_bug.cgi?id=1236316 * https://bugzilla.suse.com/show_bug.cgi?id=1236317 * https://bugzilla.suse.com/show_bug.cgi?id=1237002 * https://bugzilla.suse.com/show_bug.cgi?id=1237006 * https://bugzilla.suse.com/show_bug.cgi?id=1237008 * https://bugzilla.suse.com/show_bug.cgi?id=1237009 * https://bugzilla.suse.com/show_bug.cgi?id=1237010 * https://bugzilla.suse.com/show_bug.cgi?id=1237011 * https://bugzilla.suse.com/show_bug.cgi?id=1237012 * https://bugzilla.suse.com/show_bug.cgi?id=1237013 * https://bugzilla.suse.com/show_bug.cgi?id=1237014 . Important grub2 update for SUSE resolves several security flaws and vulnerabilities across different platforms.. SUSE Linux, grub2 update, security issues, system patching. . Severity: Important. LinuxSecurity.com Team
The container bci/openjdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2063-1 Container Tags : bci/openjdk:11 , bci/openjdk:11-30.19 , bci/openjdk:latest Container Release : 30.19 Severity : important Type : security References : 1197178 1198731 1198925 1202175 1202593 CVE-2022-35252 CVE-2022-37434 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2947-1 Released: Wed Aug 31 09:16:21 2022 Summary: Security update for zlib Type: security Severity: important References: 1202175,CVE-2022-37434 This update for zlib fixes the following issues: - CVE-2022-37434: Fixed heap-based buffer over-read or buffer overflow via large gzip header extra field (bsc#1202175). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2977-1 Released: Thu Sep 1 12:30:19 2022 Summary: Recommended update for util-linux Type: recommended Severity: moderate References: 1197178,1198731 This update for util-linux fixes the following issues: - agetty: Resolve tty name even if stdin is specified (bsc#1197178) - libmount: When moving a mount point, update all sub mount entries in utab (bsc#1198731) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2994-1 Released: Fri Sep 2 10:44:54 2022 Summary: Recommended update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau, libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame Type: recommended Severity: moderate References: 1198925 This update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau,libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame adds some missing 32bit libraries to some products. (bsc#1198925) No codechanges were done in this update. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3003-1 Released: Fri Sep 2 15:01:44 2022 Summary: Security update for curl Type: security Severity: low References: 1202593,CVE-2022-35252 This update for curl fixes the following issues: - CVE-2022-35252: Fixed a potential injection of control characters into cookies, which could be exploited by sister sites to cause a denial of service (bsc#1202593). The following package changes have been done: - libuuid1-2.37.2-150400.8.3.1 updated - libsmartcols1-2.37.2-150400.8.3.1 updated - libblkid1-2.37.2-150400.8.3.1 updated - libfdisk1-2.37.2-150400.8.3.1 updated - libz1-1.2.11-150000.3.33.1 updated - libmount1-2.37.2-150400.8.3.1 updated - libcurl4-7.79.1-150400.5.6.1 updated - util-linux-2.37.2-150400.8.3.1 updated - libxcb1-1.13-150000.3.9.1 updated - container:sles15-image-15.0.0-27.11.18 updated . Crucial security enhancement for bci/openjdk featuring updates that resolve buffer vulnerabilities and address service interruptions.. Container Security Update, bci/openjdk, Buffer Issues, SUSE Container. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for spice-gtk ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3841-1 Rating: important References: #1101295 #1104448 Cross-References: CVE-2018-10873 CVE-2018-10893 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for spice-gtk fixes the following issues: - CVE-2018-10873: Fixed a potential heap corruption when demarshalling (bsc#1104448) - CVE-2018-10893: Fixed a buffer overflow on image lz checks (bsc#1101295) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-3841=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-3841=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-3841=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2020-3841=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): libspice-client-glib-2_0-8-0.31-9.10.1 libspice-client-glib-2_0-8-debuginfo-0.31-9.10.1 libspice-client-glib-helper-0.31-9.10.1 libspice-client-glib-helper-debuginfo-0.31-9.10.1 libspice-client-gtk-2_0-4-0.31-9.10.1 libspice-client-gtk-2_0-4-debuginfo-0.31-9.10.1 libspice-client-gtk-3_0-4-0.31-9.10.1 libspice-client-gtk-3_0-4-debuginfo-0.31-9.10.1 libspice-controller0-0.31-9.10.1 libspice-controller0-debuginfo-0.31-9.10.1 spice-gtk-debuginfo-0.31-9.10.1 spice-gtk-debugsource-0.31-9.10.1 typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1 typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): libspice-client-glib-2_0-8-0.31-9.10.1 libspice-client-glib-2_0-8-debuginfo-0.31-9.10.1 libspice-client-glib-helper-0.31-9.10.1 libspice-client-glib-helper-debuginfo-0.31-9.10.1 libspice-client-gtk-2_0-4-0.31-9.10.1 libspice-client-gtk-2_0-4-debuginfo-0.31-9.10.1 libspice-client-gtk-3_0-4-0.31-9.10.1 libspice-client-gtk-3_0-4-debuginfo-0.31-9.10.1 libspice-controller0-0.31-9.10.1 libspice-controller0-debuginfo-0.31-9.10.1 spice-gtk-debuginfo-0.31-9.10.1 spice-gtk-debugsource-0.31-9.10.1 typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1 typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): libspice-client-glib-2_0-8-0.31-9.10.1 libspice-client-glib-2_0-8-debuginfo-0.31-9.10.1 libspice-client-glib-helper-0.31-9.10.1 libspice-client-glib-helper-debuginfo-0.31-9.10.1 libspice-client-gtk-2_0-4-0.31-9.10.1 libspice-client-gtk-2_0-4-debuginfo-0.31-9.10.1 libspice-client-gtk-3_0-4-0.31-9.10.1 libspice-client-gtk-3_0-4-debuginfo-0.31-9.10.1 libspice-controller0-0.31-9.10.1 libspice-controller0-debuginfo-0.31-9.10.1 spice-gtk-debuginfo-0.31-9.10.1 spice-gtk-debugsource-0.31-9.10.1 typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1 typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libspice-client-glib-2_0-8-0.31-9.10.1 libspice-client-glib-2_0-8-debuginfo-0.31-9.10.1 libspice-client-glib-helper-0.31-9.10.1 libspice-client-glib-helper-debuginfo-0.31-9.10.1 libspice-client-gtk-2_0-4-0.31-9.10.1 libspice-client-gtk-2_0-4-debuginfo-0.31-9.10.1 libspice-client-gtk-3_0-4-0.31-9.10.1 libspice-client-gtk-3_0-4-debuginfo-0.31-9.10.1 libspice-controller0-0.31-9.10.1 libspice-controller0-debuginfo-0.31-9.10.1 spice-gtk-debuginfo-0.31-9.10.1 spice-gtk-debugsource-0.31-9.10.1 typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1 typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1 References: https://www.suse.com/security/cve/CVE-2018-10873.html https://www.suse.com/security/cve/CVE-2018-10893.html https://bugzilla.suse.com/1101295 https://bugzilla.suse.com/1104448 . SUSE has released a security update for spice-gtk that addresses vulnerabilities related to heap corruption and buffer overflow across multiple distributions.. SUSE, spice-gtk, heap corruption, buffer issues, Linux security. . Severity: Important. LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2681-1 Rating: moderate References: #1103659 #1103836 #1105466 Cross-References: CVE-2017-9118 CVE-2018-14851 CVE-2018-14883 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for php53 fixes the following issues: The following security issues were fixed: - CVE-2018-14851: Fixed an out-of-bound read in exif_process_IFD_in_MAKERNOTE, which could be exploited by an attacker via crafted JPG files, and could result in an application crash. (bsc#1103659) - CVE-2018-14883: Fixed an integer overflow leading to a heap based buffer over-read in exif_thumbnail_extract of exif.c. (bsc#1103836) - CVE-2017-9118: Fixed an out of bounds access in php_pcre_replace_impl via a crafted preg_replace call (bsc#1105466) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-13773=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-13773=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-13773=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-112.38.1 php53-imap-5.3.17-112.38.1 php53-posix-5.3.17-112.38.1 php53-readline-5.3.17-112.38.1 php53-sockets-5.3.17-112.38.1 php53-sqlite-5.3.17-112.38.1 php53-tidy-5.3.17-112.38.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.38.1 php53-5.3.17-112.38.1 php53-bcmath-5.3.17-112.38.1 php53-bz2-5.3.17-112.38.1 php53-calendar-5.3.17-112.38.1 php53-ctype-5.3.17-112.38.1 php53-curl-5.3.17-112.38.1 php53-dba-5.3.17-112.38.1 php53-dom-5.3.17-112.38.1 php53-exif-5.3.17-112.38.1 php53-fastcgi-5.3.17-112.38.1 php53-fileinfo-5.3.17-112.38.1 php53-ftp-5.3.17-112.38.1 php53-gd-5.3.17-112.38.1 php53-gettext-5.3.17-112.38.1 php53-gmp-5.3.17-112.38.1 php53-iconv-5.3.17-112.38.1 php53-intl-5.3.17-112.38.1 php53-json-5.3.17-112.38.1 php53-ldap-5.3.17-112.38.1 php53-mbstring-5.3.17-112.38.1 php53-mcrypt-5.3.17-112.38.1 php53-mysql-5.3.17-112.38.1 php53-odbc-5.3.17-112.38.1 php53-openssl-5.3.17-112.38.1 php53-pcntl-5.3.17-112.38.1 php53-pdo-5.3.17-112.38.1 php53-pear-5.3.17-112.38.1 php53-pgsql-5.3.17-112.38.1 php53-pspell-5.3.17-112.38.1 php53-shmop-5.3.17-112.38.1 php53-snmp-5.3.17-112.38.1 php53-soap-5.3.17-112.38.1 php53-suhosin-5.3.17-112.38.1 php53-sysvmsg-5.3.17-112.38.1 php53-sysvsem-5.3.17-112.38.1 php53-sysvshm-5.3.17-112.38.1 php53-tokenizer-5.3.17-112.38.1 php53-wddx-5.3.17-112.38.1 php53-xmlreader-5.3.17-112.38.1 php53-xmlrpc-5.3.17-112.38.1 php53-xmlwriter-5.3.17-112.38.1 php53-xsl-5.3.17-112.38.1 php53-zip-5.3.17-112.38.1 php53-zlib-5.3.17-112.38.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.38.1 php53-debugsource-5.3.17-112.38.1 References: https://www.suse.com/security/cve/CVE-2017-9118.html https://www.suse.com/security/cve/CVE-2018-14851.html https://www.suse.com/security/cve/CVE-2018-14883.html https://bugzilla.suse.com/1103659 https://bugzilla.suse.com/1103836 https://bugzilla.suse.com/1105466 _______________________________________________ sle-security-updates mailing list
Updated libtasn1 packages that fix three security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libtasn1 security update Advisory ID: RHSA-2014:0596-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0596.html Issue date: 2014-06-03 CVE Names: CVE-2014-3467 CVE-2014-3468 CVE-2014-3469 ==================================================================== 1. Summary: Updated libtasn1 packages that fix three security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The libtasn1 library provides Abstract Syntax Notation One (ASN.1) parsing and structures management, and Distinguished Encoding Rules (DER) encoding and decoding functions. It was discovered that the asn1_get_bit_der() function of the libtasn1 library incorrectly reported the length of ASN.1-encoded data.Specially crafted ASN.1 input could cause an application using libtasn1 to perform an out-of-bounds access operation, causing the application to crash or, possibly, execute arbitrary code. (CVE-2014-3468) Multiple incorrect buffer boundary check issues were discovered in libtasn1. Specially crafted ASN.1 input could cause an application using libtasn1 to crash. (CVE-2014-3467) Multiple NULL pointer dereference flaws were found in libtasn1's asn1_read_value() function. Specially crafted ASN.1 input could cause an application using libtasn1 to crash, if the application used the aforementioned function in a certain way. (CVE-2014-3469) Red Hat would like to thank GnuTLS upstream for reporting these issues. All libtasn1 users are advised to upgrade to these updated packages, which correct these issues. For the update to take effect, all applications linked to the libtasn1 library must be restarted. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1102022 - CVE-2014-3467 libtasn1: multiple boundary check issues 1102323 - CVE-2014-3468 libtasn1: asn1_get_bit_der() can return negative bit length 1102329 - CVE-2014-3469 libtasn1: asn1_read_value_type() NULL pointer dereference 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: libtasn1-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.i686.rpm x86_64: libtasn1-2.3-6.el6_5.i686.rpm libtasn1-2.3-6.el6_5.x86_64.rpm libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): Source: i386: libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-devel-2.3-6.el6_5.i686.rpm libtasn1-tools-2.3-6.el6_5.i686.rpm x86_64: libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm libtasn1-devel-2.3-6.el6_5.i686.rpm libtasn1-devel-2.3-6.el6_5.x86_64.rpm libtasn1-tools-2.3-6.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: libtasn1-2.3-6.el6_5.i686.rpm libtasn1-2.3-6.el6_5.x86_64.rpm libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm libtasn1-devel-2.3-6.el6_5.i686.rpm libtasn1-devel-2.3-6.el6_5.x86_64.rpm libtasn1-tools-2.3-6.el6_5.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: libtasn1-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-devel-2.3-6.el6_5.i686.rpm ppc64: libtasn1-2.3-6.el6_5.ppc.rpm libtasn1-2.3-6.el6_5.ppc64.rpm libtasn1-debuginfo-2.3-6.el6_5.ppc.rpm libtasn1-debuginfo-2.3-6.el6_5.ppc64.rpm libtasn1-devel-2.3-6.el6_5.ppc.rpm libtasn1-devel-2.3-6.el6_5.ppc64.rpm s390x: libtasn1-2.3-6.el6_5.s390.rpm libtasn1-2.3-6.el6_5.s390x.rpm libtasn1-debuginfo-2.3-6.el6_5.s390.rpm libtasn1-debuginfo-2.3-6.el6_5.s390x.rpm libtasn1-devel-2.3-6.el6_5.s390.rpm libtasn1-devel-2.3-6.el6_5.s390x.rpm x86_64: libtasn1-2.3-6.el6_5.i686.rpm libtasn1-2.3-6.el6_5.x86_64.rpm libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm libtasn1-devel-2.3-6.el6_5.i686.rpm libtasn1-devel-2.3-6.el6_5.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-tools-2.3-6.el6_5.i686.rpm ppc64: libtasn1-debuginfo-2.3-6.el6_5.ppc64.rpm libtasn1-tools-2.3-6.el6_5.ppc64.rpm s390x: libtasn1-debuginfo-2.3-6.el6_5.s390x.rpm libtasn1-tools-2.3-6.el6_5.s390x.rpm x86_64: libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm libtasn1-tools-2.3-6.el6_5.x86_64.rpm RedHat Enterprise Linux Workstation (v. 6): Source: i386: libtasn1-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-devel-2.3-6.el6_5.i686.rpm x86_64: libtasn1-2.3-6.el6_5.i686.rpm libtasn1-2.3-6.el6_5.x86_64.rpm libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm libtasn1-devel-2.3-6.el6_5.i686.rpm libtasn1-devel-2.3-6.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: libtasn1-debuginfo-2.3-6.el6_5.i686.rpm libtasn1-tools-2.3-6.el6_5.i686.rpm x86_64: libtasn1-debuginfo-2.3-6.el6_5.x86_64.rpm libtasn1-tools-2.3-6.el6_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2014-3467 https://access.redhat.com/security/cve/CVE-2014-3468 https://access.redhat.com/security/cve/CVE-2014-3469 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTjfmLXlSAg2UNWIIRAs5/AKCzvlEpaoQWK1Nb3hm0f+14BycQXACeOjyh 3xJPUdZgrwhgadFwaeElDDo=FDUn -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2032-1
Get the latest Linux and open source security news straight to your inbox.