Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#1202812 * bsc#1216005 Cross-References: * CVE-2022-2990 . # Security update for buildah Announcement ID: SUSE-SU-2023:4099-1 Rating: moderate References: * bsc#1202812 * bsc#1216005 Cross-References: * CVE-2022-2990 CVSS scores: * CVE-2022-2990 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2022-2990 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE CaaS Platform 4.0 * SUSE Enterprise Storage 7 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for buildah fixes the following issues: * CVE-2022-2990: Fixed a flaw which might allow sensitive information disclosure or possible data modification. (bsc#1202812) * buildah is also rebuilt against go1.21. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4099=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4099=1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4099=1 * SUSE LinuxEnterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4099=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4099=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4099=1 * SUSE Enterprise Storage 7 zypper in -t patch SUSE-Storage-7-2023-4099=1 * SUSE CaaS Platform 4.0 To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Enterprise Storage 7 (aarch64 x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE CaaS Platform 4.0 (x86_64) * buildah-1.25.1-150100.3.20.15 ## References: * https://www.suse.com/security/cve/CVE-2022-2990.html * https://bugzilla.suse.com/show_bug.cgi?id=1202812 * https://bugzilla.suse.com/show_bug.cgi?id=1216005 . A recent SUSE buildah update addresses a moderate severity vulnerability, enhancing security for applications using buildah in container image management. SUSE Update, Buildah Security, Data Protection, Security Patch. . LinuxSecurity.com Team
Multiple vunerabilities were discovered in rails, the Ruby based server-side MVC web application framework, which could result in XSS, data disclosure and open redirect. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5372-1
Elton Nokaj discovered that incorrect error handling in Bottle, a WSGI framework for Python, could result in the disclosure of sensitive information. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5159-1
An issue has been found in package atftp, an advanced TFTP client/server. Due to missing bound checks, data could be read behind a buffer so that . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3028-1
rclone uses weak random number generation such that generated passwords can be easily cracked.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: rclone: Weak random number generation Date: July 08, 2021 Bugs: #755638 ID: 202107-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= rclone uses weak random number generation such that generated passwords can be easily cracked. Background ========= rclone is a problem to sync files to and from various cloud storage providers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/rclone < 1.53.3 > = 1.53.3 Description ========== Passwords generated with rclone were insecurely generated and are vulnerable to brute force attacks. Impact ===== Data kept secret with a password generated by rclone may be disclosed to a local attacker. Workaround ========= There is no known workaround at this time. Resolution ========= All rclone users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/rclone-1.53.3" References ========= [ 1 ] CVE-2020-28924 https://nvd.nist.gov/vuln/detail/CVE-2020-28924 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-14 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machinesis of utmost importance to us. Any security concerns should be addressed to
TELNET stack contents disclosure (CVE-2021-22898). References: - https://bugs.mageia.org/show_bug.cgi?id=28971 - https://curl.se/docs/CVE-2021-22898.html . MGASA-2021-0243 - Updated curl packages fix a security vulnerability Publication date: 08 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0243.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-22898 TELNET stack contents disclosure (CVE-2021-22898). References: - https://bugs.mageia.org/show_bug.cgi?id=28971 - https://curl.se/docs/CVE-2021-22898.html - https://lists.fedoraproject.org/archives/list/
Buffer overrun from integer overflow in array subscripting calculations (CVE-2021-32027). Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE. (CVE-2021-32028). Memory disclosure in partitioned-table UPDATE ... RETURNING. (CVE-2021-32029). . MGASA-2021-0221 - Updated postgresql packages fix security vulnerabilities Publication date: 23 May 2021 URL: https://advisories.mageia.org/MGASA-2021-0221.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-32027, CVE-2021-32029, CVE-2021-32029 Buffer overrun from integer overflow in array subscripting calculations (CVE-2021-32027). Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE. (CVE-2021-32028). Memory disclosure in partitioned-table UPDATE ... RETURNING. (CVE-2021-32029). References: - https://bugs.mageia.org/show_bug.cgi?id=28929 - https://www.postgresql.org/about/news/postgresql-133-127-1112-1017-and-9622-released-2210/ - https://www.cve.org/CVERecord?id=CVE-2021-32027 - https://www.cve.org/CVERecord?id=CVE-2021-32029 - https://www.cve.org/CVERecord?id=CVE-2021-32029 SRPMS: - 8/core/postgresql11-11.12-1.mga8 - 8/core/postgresql13-13.3-1.mga8 - 7/core/postgresql9.6-9.6.22-1.mga7 - 7/core/postgresql11-11.12-1.mga7 . Recent updates to PostgreSQL packages as indicated by Mageia's security advisory have successfully resolved issues related to buffer overflow and memory leak vulnerabilities.. PostgreSQL Security, Mageia Updates, Memory Issues. . Severity: Critical. LinuxSecurity.com Team
Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, . MGASA-2020-0163 - Updated firefox packages fix security vulnerabilities Publication date: 08 Apr 2020 URL: https://advisories.mageia.org/MGASA-2020-0163.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-XXXX Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure (CVE-2020-6821). On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code (CVE-2020-6822). Mozilla developers Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2020-6825). References: - https://bugs.mageia.org/show_bug.cgi?id=26442 - https://www.mozilla.org/en-US/security/advisories/mfsa2020-13/ - https://www.cve.org/CVERecord?id=CVE-2019-XXXX SRPMS: - 7/core/firefox-68.7.0-1.mga7 - 7/core/firefox-l10n-68.7.0-1.mga7 . Mageia 2020-0174: Enhanced Chrome resolves security vulnerabilities and prospective threats. Discover the full report now!. Firefox Update, Mageia Security, Memory Safety, CVE-2020-6821, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.