The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:279-1 Container Tags : suse/sles12sp4:26.424 , suse/sles12sp4:latest Container Release : 26.424 Severity : important Type : security References : 1196025 1196249 1196784 1196877 CVE-2022-0778 CVE-2022-25236 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:842-1 Released: Tue Mar 15 11:32:49 2022 Summary: Security update for expat Type: security Severity: important References: 1196025,1196784,CVE-2022-25236 This update for expat fixes the following issues: - Fixed a regression caused by the patch for CVE-2022-25236 (bsc#1196784). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:857-1 Released: Tue Mar 15 19:33:24 2022 Summary: Security update for openssl-1_0_0 Type: security Severity: important References: 1196249,1196877,CVE-2022-0778 This update for openssl-1_0_0 fixes the following issues: - CVE-2022-0778: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (bsc#1196877). - Allow CRYPTO_THREADID_set_callback to be called with NULL parameter (bsc#1196249). The following package changes have been done: - base-container-licenses-3.0-1.273 updated - container-suseconnect-2.0.0-1.165 updated - libexpat1-2.1.0-21.22.1 updated - libopenssl1_0_0-1.0.2p-3.48.1 updated - openssl-1_0_0-1.0.2p-3.48.1 updated . SUSE Container Security Notice SUSE-CU-2022:280-1 addresses urgent updates regarding glibc and curl security flaws.. suse container update, security patches, expat update, openssl issues. . Severity: Important.LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for expat ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0495-1 Rating: important References: #1195054 #1195217 Cross-References: CVE-2022-23852 CVE-2022-23990 CVSS scores: CVE-2022-23852 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23852 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23990 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23990 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: HPE Helion Openstack 8 SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for expat fixes the following issues: - CVE-2022-23852: Fixed signed integer overflow in XML_GetBuffer (bsc#1195054). - CVE-2022-23990: Fixed integer overflow in the doProlog function (bsc#1195217). Patch Instructions: To install this SUSE Security Update use the SUSE recommendedinstallation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-495=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-495=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-495=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-495=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-495=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2022-495=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2022-495=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-495=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2022-495=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2022-495=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-495=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-495=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-495=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debuginfo-32bit-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debuginfo-32bit-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE OpenStack Cloud 9 (x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debuginfo-32bit-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE OpenStack Cloud 8 (x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debuginfo-32bit-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): expat-debuginfo-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat-devel-2.1.0-21.15.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): expat-debuginfo-32bit-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): expat-debuginfo-32bit-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): expat-debuginfo-32bit-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (s390x x86_64): expat-debuginfo-32bit-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x x86_64): expat-debuginfo-32bit-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debuginfo-32bit-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debuginfo-32bit-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 - HPE Helion Openstack 8 (x86_64): expat-2.1.0-21.15.1 expat-debuginfo-2.1.0-21.15.1 expat-debuginfo-32bit-2.1.0-21.15.1 expat-debugsource-2.1.0-21.15.1 libexpat1-2.1.0-21.15.1 libexpat1-32bit-2.1.0-21.15.1 libexpat1-debuginfo-2.1.0-21.15.1 libexpat1-debuginfo-32bit-2.1.0-21.15.1 References: https://www.suse.com/security/cve/CVE-2022-23852.html https://www.suse.com/security/cve/CVE-2022-23990.html https://bugzilla.suse.com/1195054 https://bugzilla.suse.com/1195217 . Ubuntu Security Patch: Critical expat solution released for various versions mitigating severe vulnerabilities.. SUSE Security Update, expat Software Fix, integer Overflow Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for expat ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1523-1 Rating: important References: #979441 #980391 Cross-References: CVE-2015-1283 CVE-2016-0718 Affected Products: openSUSE Leap 42.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for expat fixes the following issues: Security issue fixed: - CVE-2016-0718: Fix Expat XML parser that mishandles certain kinds of malformed input documents. (bsc#979441) - CVE-2015-1283: Fix multiple integer overflows. (bnc#980391) This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2016-695=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.1 (i586 x86_64): expat-2.1.0-17.1 expat-debuginfo-2.1.0-17.1 expat-debugsource-2.1.0-17.1 libexpat-devel-2.1.0-17.1 libexpat1-2.1.0-17.1 libexpat1-debuginfo-2.1.0-17.1 - openSUSE Leap 42.1 (x86_64): expat-debuginfo-32bit-2.1.0-17.1 libexpat-devel-32bit-2.1.0-17.1 libexpat1-32bit-2.1.0-17.1 libexpat1-debuginfo-32bit-2.1.0-17.1 References: https://www.suse.com/security/cve/CVE-2015-1283.html https://www.suse.com/security/cve/CVE-2016-0718.html https://bugzilla.suse.com/979441 https://bugzilla.suse.com/980391 -- . Tackling significant vulnerabilities in expat for openSUSE Leap 42.1 through essential patches.. openSUSE, Security Update, Expat Parser Fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.