Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: java-11-openjdk security and bug fix update Advisory ID: RHSA-2022:7008-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7008 Issue date: 2022-10-19 CVE Names: CVE-2022-21618 CVE-2022-21619 CVE-2022-21624 CVE-2022-21626 CVE-2022-21628 CVE-2022-39399 ==================================================================== 1. Summary: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Security Fix(es): * OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) (CVE-2022-21618) * OpenJDK: excessive memory allocation in X.509certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619) * OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624) * OpenJDK: missing SNI caching in HTTP/2 (Networking, 8289366) (CVE-2022-39399) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream release (2022-10, 11.0.17) (BZ#2130373) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2130373 - Prepare for the next quarterly OpenJDK upstream release (2022-10, 11.0.17) [rhel-7.9.z] 2133745 - CVE-2022-21619 OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) 2133753 - CVE-2022-21626 OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) 2133765 - CVE-2022-21624 OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) 2133769 - CVE-2022-21628 OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) 2133776 - CVE-2022-39399 OpenJDK: missing SNI caching in HTTP/2 (Networking, 8289366) 2133817 - CVE-2022-21618 OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) 6. Package List: Red Hat Enterprise Linux Client (v.7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm ppc64: java-11-openjdk-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.ppc64.rpm ppc64le: java-11-openjdk-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.ppc64le.rpm s390x: java-11-openjdk-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.s390x.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.ppc64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.ppc64.rpm ppc64le: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.ppc64le.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.ppc64le.rpm s390x: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.s390x.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.s390x.rpm x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: java-11-openjdk-11.0.17.0.8-2.el7_9.src.rpm x86_64: java-11-openjdk-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-devel-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-headless-11.0.17.0.8-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-demo-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-jmods-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-src-11.0.17.0.8-2.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.17.0.8-2.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-21618 https://access.redhat.com/security/cve/CVE-2022-21619 https://access.redhat.com/security/cve/CVE-2022-21624 https://access.redhat.com/security/cve/CVE-2022-21626 https://access.redhat.com/security/cve/CVE-2022-21628 https://access.redhat.com/security/cve/CVE-2022-39399 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGINPGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY1C5JNzjgjWX9erEAQhj8w//RUsDzgmgcttv7giIGG2ft9H1JMK1WmSb nA+p0bGt9jA5yp7HTxRKgfIQ9bop2+ZKh7NOj8qMyhnW9QUxGraGwmHcLOEoPV27 +yUbmyx6Vwt2gc+fyd/9VDpmH6ugtyWH0tsEx/gOXB6lina41CC0izdIt2LdcM83 tb+uQenxQd9a7V0MZfYVCiTIlo4D0IDm+rvgUtYRhZF2AbAPngH4rUj3SLUdnwMi 60KqTVmwcv6RQ2xZNbkrtDos9OgVLWqRJ9pspLe81KPW06+afkjm9Dl6e03eDd26 IK7Qmp4DgKrrInIECAVox/qQFS+8UjIleUbzvD9AOZdTSZkoUY6kqbj1EHJF8PBF bGfKa4Gn1IEnz6jWXc+0lzpmm+j5//99Uea4AhQPPNpPAiwkUSxQqeyM0g50JIx1 HkXjgXxNns2FR46/3rZzXTyObXGJVr1TyG9R1OxUAnObS90lZhsJcWdL55tgOUqr kigCwf0a6waJ2cN9yArnzywDBhWKR+FflnurxKrG7Lq5Q2Xmpsv0wKGVKjFIgzrv kly11Tq/E5r8TYy7zyTXR/j50jAqVLog4NQNaUGGxUtHdlTrWa1E1UFxPLMAZZES YnRejAecsDbrzHyzAYrvXMSbykNH6BQ2o9NpTs6zAb4AME+mPwhFQc/WkH5+8TR4 RyoR8MMXBXc=RFnE -----END PGP SIGNATURE----- -- RHSA-announce mailing list
openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssl-1.0.2k-25.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-25.el7_9.i686.rpm openssl-debuginfo-1.0.2k-25.el7_9.x86_64.rpm ope [More...]. Synopsis: Important: openssl security update Advisory ID: SLSA-2022:1066-1 Issue Date: 2022-03-28 CVE Numbers: CVE-2022-0778 -- Security Fix(es): * openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 openssl-1.0.2k-25.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-25.el7_9.i686.rpm openssl-debuginfo-1.0.2k-25.el7_9.x86_64.rpm openssl-libs-1.0.2k-25.el7_9.i686.rpm openssl-libs-1.0.2k-25.el7_9.x86_64.rpm openssl-devel-1.0.2k-25.el7_9.i686.rpm openssl-devel-1.0.2k-25.el7_9.x86_64.rpm openssl-perl-1.0.2k-25.el7_9.x86_64.rpm openssl-static-1.0.2k-25.el7_9.i686.rpm openssl-static-1.0.2k-25.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical patch for OpenSSL on Scientific Linux released to resolve a potential infinite loop vulnerability during the certificate parsing process.. openssl update, Scientific Linux advisory, security fix openssl. . Severity: Critical. LinuxSecurity.com Team
Infinite loop in BN_mod_sqrt() reachable when parsing certificates. (CVE-2022-0778) References: - https://bugs.mageia.org/show_bug.cgi?id=30174 . MGASA-2022-0113 - Updated openssl packages fix security vulnerability Publication date: 23 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0113.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0778 Infinite loop in BN_mod_sqrt() reachable when parsing certificates. (CVE-2022-0778) References: - https://bugs.mageia.org/show_bug.cgi?id=30174 - https://openssl-library.org/news/secadv/20220315.txt - https://ubuntu.com/security/notices/USN-5328-1 - https://www.cve.org/CVERecord?id=CVE-2022-0778 SRPMS: - 8/core/openssl-1.1.1n-1.mga8 . The patch for Fedora tackles a severe openssl vulnerability—a never-ending cycle in parsing certificates.. Mageia Security Advisory, OpenSSL Update, Certificate Parsing Issues, Security Fixes. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0854-1 Rating: important References: #1196877 Cross-References: CVE-2022-0778 CVSS scores: CVE-2022-0778 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: HPE Helion Openstack 8 SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server for SAP 12-SP3 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl fixes the following issues: - CVE-2022-0778: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (bsc#1196877). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-854=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-854=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2022-854=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2022-854=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-854=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-854=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-854=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE OpenStack Cloud 8 (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE OpenStack Cloud 8 (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x x86_64): libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): openssl-doc-1.0.2j-60.75.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 - HPE Helion Openstack 8 (noarch): openssl-doc-1.0.2j-60.75.1 - HPE Helion Openstack 8 (x86_64): libopenssl-devel-1.0.2j-60.75.1 libopenssl1_0_0-1.0.2j-60.75.1 libopenssl1_0_0-32bit-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-1.0.2j-60.75.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.75.1 libopenssl1_0_0-hmac-1.0.2j-60.75.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.75.1 openssl-1.0.2j-60.75.1 openssl-debuginfo-1.0.2j-60.75.1 openssl-debugsource-1.0.2j-60.75.1 References: https://www.suse.com/security/cve/CVE-2022-0778.html https://bugzilla.suse.com/1196877 . An essential patch for openssl has been released, targeting a significant concern for SUSE users related to certificate management.. SUSE Security Update, OpenSSL Patch, Important Vulnerability. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for libqt5-qtbase ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2357-1 Rating: moderate References: #1172726 #1173758 Cross-References: CVE-2020-13962 Affected Products: SUSE Linux Enterprise Module for Desktop Applications 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libqt5-qtbase fixes the following issues: - Fixed a possible crash in certificate parsing. - Fixed a DoS in QSslSocket (bsc#1172726, CVE-2020-13962). - Added support for PostgreSQL 12 (bsc#1173758). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-2357=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-2357=1 Package List: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (aarch64 ppc64le s390x x86_64): libQt5OpenGLExtensions-devel-static-5.12.7-4.3.1 libQt5Sql5-mysql-5.12.7-4.3.1 libQt5Sql5-mysql-debuginfo-5.12.7-4.3.1 libQt5Sql5-postgresql-5.12.7-4.3.1 libQt5Sql5-postgresql-debuginfo-5.12.7-4.3.1 libQt5Sql5-unixODBC-5.12.7-4.3.1 libQt5Sql5-unixODBC-debuginfo-5.12.7-4.3.1 libqt5-qtbase-debugsource-5.12.7-4.3.1 libqt5-qtbase-platformtheme-gtk3-5.12.7-4.3.1 libqt5-qtbase-platformtheme-gtk3-debuginfo-5.12.7-4.3.1 - SUSELinux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libQt5Concurrent-devel-5.12.7-4.3.1 libQt5Concurrent5-5.12.7-4.3.1 libQt5Concurrent5-debuginfo-5.12.7-4.3.1 libQt5Core-devel-5.12.7-4.3.1 libQt5Core5-5.12.7-4.3.1 libQt5Core5-debuginfo-5.12.7-4.3.1 libQt5DBus-devel-5.12.7-4.3.1 libQt5DBus-devel-debuginfo-5.12.7-4.3.1 libQt5DBus5-5.12.7-4.3.1 libQt5DBus5-debuginfo-5.12.7-4.3.1 libQt5Gui-devel-5.12.7-4.3.1 libQt5Gui5-5.12.7-4.3.1 libQt5Gui5-debuginfo-5.12.7-4.3.1 libQt5KmsSupport-devel-static-5.12.7-4.3.1 libQt5Network-devel-5.12.7-4.3.1 libQt5Network5-5.12.7-4.3.1 libQt5Network5-debuginfo-5.12.7-4.3.1 libQt5OpenGL-devel-5.12.7-4.3.1 libQt5OpenGL5-5.12.7-4.3.1 libQt5OpenGL5-debuginfo-5.12.7-4.3.1 libQt5PlatformHeaders-devel-5.12.7-4.3.1 libQt5PlatformSupport-devel-static-5.12.7-4.3.1 libQt5PrintSupport-devel-5.12.7-4.3.1 libQt5PrintSupport5-5.12.7-4.3.1 libQt5PrintSupport5-debuginfo-5.12.7-4.3.1 libQt5Sql-devel-5.12.7-4.3.1 libQt5Sql5-5.12.7-4.3.1 libQt5Sql5-debuginfo-5.12.7-4.3.1 libQt5Sql5-sqlite-5.12.7-4.3.1 libQt5Sql5-sqlite-debuginfo-5.12.7-4.3.1 libQt5Test-devel-5.12.7-4.3.1 libQt5Test5-5.12.7-4.3.1 libQt5Test5-debuginfo-5.12.7-4.3.1 libQt5Widgets-devel-5.12.7-4.3.1 libQt5Widgets5-5.12.7-4.3.1 libQt5Widgets5-debuginfo-5.12.7-4.3.1 libQt5Xml-devel-5.12.7-4.3.1 libQt5Xml5-5.12.7-4.3.1 libQt5Xml5-debuginfo-5.12.7-4.3.1 libqt5-qtbase-common-devel-5.12.7-4.3.1 libqt5-qtbase-common-devel-debuginfo-5.12.7-4.3.1 libqt5-qtbase-debugsource-5.12.7-4.3.1 libqt5-qtbase-devel-5.12.7-4.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (noarch): libQt5Core-private-headers-devel-5.12.7-4.3.1 libQt5DBus-private-headers-devel-5.12.7-4.3.1 libQt5Gui-private-headers-devel-5.12.7-4.3.1 libQt5KmsSupport-private-headers-devel-5.12.7-4.3.1 libQt5Network-private-headers-devel-5.12.7-4.3.1 libQt5OpenGL-private-headers-devel-5.12.7-4.3.1 libQt5PlatformSupport-private-headers-devel-5.12.7-4.3.1 libQt5PrintSupport-private-headers-devel-5.12.7-4.3.1 libQt5Sql-private-headers-devel-5.12.7-4.3.1 libQt5Test-private-headers-devel-5.12.7-4.3.1 libQt5Widgets-private-headers-devel-5.12.7-4.3.1 libqt5-qtbase-private-headers-devel-5.12.7-4.3.1 References: https://www.suse.com/security/cve/CVE-2020-13962.html https://bugzilla.suse.com/1172726 https://bugzilla.suse.com/1173758 _______________________________________________ sle-security-updates mailing list
It was discovered that the original patch applied for CVE-2016-2182 in DSA-3673-1 was incomplete, causing a regression when parsing certificates. Updated packages are now available to address this problem. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3673-2
Get the latest Linux and open source security news straight to your inbox.