The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1-1 Container Tags : suse/sle15:15.0 , suse/sle15:15.0.4.22.660 Container Release : 4.22.660 Severity : important Type : security References : 1206212 1206622 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3-1 Released: Mon Jan 2 09:54:15 2023 Summary: Security update for ca-certificates-mozilla Type: security Severity: important References: 1206212,1206622 This update for ca-certificates-mozilla fixes the following issues: - Updated to 2.60 state of Mozilla SSL root CAs (bsc#1206622) Removed CAs: - Global Chambersign Root - EC-ACC - Network Solutions Certificate Authority - Staat der Nederlanden EV Root CA - SwissSign Platinum CA - G2 Added CAs: - DIGITALSIGN GLOBAL ROOT ECDSA CA - DIGITALSIGN GLOBAL ROOT RSA CA - Security Communication ECC RootCA1 - Security Communication RootCA3 Changed trust: - TrustCor certificates only trusted up to Nov 30 (bsc#1206212) - Removed CAs (bsc#1206212) as most code does not handle 'valid before nov 30 2022' and it is not clear how many certs were issued for SSL middleware by TrustCor: - TrustCor RootCert CA-1 - TrustCor RootCert CA-2 - TrustCor ECA-1 The following package changes have been done: - ca-certificates-mozilla-2.60-150000.4.38.1 updated . Vital security enhancement for SUSE Container suse/sle15 consists of essential certificate modifications.. SUSE Container Update, Security Update, ca-certificates-mozilla. . Severity: Important. LinuxSecurity.com Team
Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson References: - https://bugs.mageia.org/show_bug.cgi?id=31232 . MGASA-2022-0462 - Updated rootcerts packages fix security vulnerability Publication date: 13 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0462.html Type: security Affected Mageia releases: 8 Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson References: - https://bugs.mageia.org/show_bug.cgi?id=31232 - https://phabricator.services.mozilla.com/D163527 - SRPMS: - 8/core/rootcerts-20221130.00-1.mga8 . MGASA-2022-0463 enhanced webserver packages addressing critical security issues, released on December 14, 2022.. Mageia Update, TrustCor Certificates, Security Fix, Root Certificates, Certificate Management. . LinuxSecurity.com Team
The CA certificates in the ca-certificates package were updated.. =========================================================================Ubuntu Security Notice USN-5473-1 June 08, 2022 ca-certificates update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: The CA certificates in the ca-certificates package were updated. Software Description: - ca-certificates: Common CA certificates Details: The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 2.50 version of the Mozilla certificate authority bundle. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: ca-certificates 20211016~21.10.1 Ubuntu 20.04 LTS: ca-certificates 20211016~20.04.1 Ubuntu 18.04 LTS: ca-certificates 20211016~18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5473-1 https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/1976631 Package Information: https://launchpad.net/ubuntu/+source/ca-certificates/20211016~21.10.1 https://launchpad.net/ubuntu/+source/ca-certificates/20211016~20.04.1 https://launchpad.net/ubuntu/+source/ca-certificates/20211016~18.04.1 . On June 08, 2022, Ubuntu enhanced its CA certificates package to address vulnerabilities in previous versions.. CA Certificates Update, Ubuntu Security Notice, Package Update. . LinuxSecurity.com Team
This update reverts the Symantec CA blacklist (which was originally #911289). The following root certificates were added back (+): + "GeoTrust Global CA" + "GeoTrust Primary Certification Authority" . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2593-1
The CA certificates in the ca-certificates package were updated.. =========================================================================Ubuntu Security Notice USN-4719-1 February 02, 2021 ca-certificates update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: The CA certificates in the ca-certificates package were updated. Software Description: - ca-certificates: Common CA certificates Details: The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 2.46 version of the Mozilla certificate authority bundle. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: ca-certificates 20210119~20.10.1 Ubuntu 20.04 LTS: ca-certificates 20210119~20.04.1 Ubuntu 18.04 LTS: ca-certificates 20210119~18.04.1 Ubuntu 16.04 LTS: ca-certificates 20210119~16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4719-1 https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/1914064 Package Information: https://launchpad.net/ubuntu/+source/ca-certificates/20210119~20.10.1 https://launchpad.net/ubuntu/+source/ca-certificates/20210119~20.04.1 https://launchpad.net/ubuntu/+source/ca-certificates/20210119~18.04.1 https://launchpad.net/ubuntu/+source/ca-certificates/20210119~16.04.1 . The SSL certificate bundle in Debian has undergone a significant revision, replacing obsolete certificates with the most current set.. Ubuntu Security Update, CA Certificates Update, Authority Package. . LinuxSecurity.com Team
The CA certificates in the ca-certificates package were updated.. =========================================================================Ubuntu Security Notice USN-4608-1 October 28, 2020 ca-certificates update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: The CA certificates in the ca-certificates package were updated. Software Description: - ca-certificates: Common CA certificates Details: The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 2.44 version of the Mozilla certificate authority bundle. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: ca-certificates 20201027ubuntu0.20.10.1 Ubuntu 20.04 LTS: ca-certificates 20201027ubuntu0.20.04.1 Ubuntu 18.04 LTS: ca-certificates 20201027ubuntu0.18.04.1 Ubuntu 16.04 LTS: ca-certificates 20201027ubuntu0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/1900727 Package Information: https://launchpad.net/ubuntu/+source/ca-certificates/20201027ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/ca-certificates/20201027ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/ca-certificates/20201027ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/ca-certificates/20201027ubuntu0.16.04.1 . Keep your Ubuntu system secure by routinely updating CA certificates. Follow this simple guide to stay protected against vulnerabilities.. CA Certificates Update, Ubuntu Security Notice, Package Update, CA Certificates. . Severity: Important. LinuxSecurity.com Team
An expired certificate was removed from ca-certificates.. =========================================================================Ubuntu Security Notice USN-4377-2 June 01, 2020 ca-certificates update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: An expired certificate was removed from ca-certificates. Software Description: - ca-certificates: Common CA certificates Details: USN-4377-1 updated ca-certificates. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: The ca-certificates package contained an expired CA certificate that caused connectivity issues. This update removes the "AddTrust External Root" CA. In addition, on Ubuntu 12.04 ESM and Ubuntu 14.04 ESM, this update refreshes the included certificates to those contained in the 20190110 package. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: ca-certificates 20190110~14.04.1~esm1 Ubuntu 12.04 ESM: ca-certificates 20190110~12.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4377-2 https://ubuntu.com/security/notices/USN-4377-1 . An outdated certificate has been deleted from the Ubuntu ca-certificates package, resolving connection problems. Update is available for impacted versions.. Ubuntu Security, ca-certificates, certificate update, expired certificates. . LinuxSecurity.com Team
This is an update to version 2.24 of the Mozilla CA trust list, which has been published as part of the NSS 3.37 release. Please refer to the upstream release notes for the changes: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ed35b82337 2018-05-31 12:05:51.375212 --------------------------------------------------------------------------------Name : ca-certificates Product : Fedora 27 Version : 2018.2.24 Release : 1.0.fc27 URL : https://fedoraproject.org/wiki/CA-Certificates Summary : The Mozilla CA root certificate bundle Description : This package contains the set of CA certificates chosen by the Mozilla Foundation for use with the Internet PKI. --------------------------------------------------------------------------------Update Information: This is an update to version 2.24 of the Mozilla CA trust list, which has been published as part of the NSS 3.37 release. Please refer to the upstream release notes for the changes: --------------------------------------------------------------------------------ChangeLog: * Fri May 18 2018 Kai Engert - 2018.2.24-1.0 - Update to CKBI 2.24 from NSS 3.37 * Tue Feb 6 2018 Kai Engert - 2018.2.22-1.0 - Update to CKBI 2.22 from NSS 3.35 * Mon Nov 27 2017 Kai Engert - 2017.2.20-1.0 - Update to CKBI 2.20 from NSS 3.34.1 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-ed35b82337' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.