* bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235 . # Security update for cups Announcement ID: SUSE-SU-2024:2003-2 Rating: important References: * bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235 CVSS scores: * CVE-2024-35235 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for cups fixes the following issues: * CVE-2024-35235: Fixed a bug in cupsd that could allow an attacker to change the permissions of other files in the system. (bsc#1225365) * Handle local 'Negotiate' authentication response for cli clients (bsc#1223179) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-2003=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libcups2-2.2.7-150000.3.59.1 * cups-debuginfo-2.2.7-150000.3.59.1 * cups-debugsource-2.2.7-150000.3.59.1 * libcups2-debuginfo-2.2.7-150000.3.59.1 * cups-config-2.2.7-150000.3.59.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35235.html * https://bugzilla.suse.com/show_bug.cgi?id=1223179 * https://bugzilla.suse.com/show_bug.cgi?id=1225365 . Crucial patch for CUPS resolves possible alterations in file access rights for SUSE Linux Enterprise Micro 5.5.. SUSE Linux Enterprise, CUPS Update, Important Security Advisory, File Permission Fix. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for glib2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1596-1 Rating: important References: #1107116 #1107121 #1111499 #1137001 Cross-References: CVE-2018-16428 CVE-2018-16429 CVE-2019-12450 Affected Products: SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for glib2 fixes the following issues: Security issues fixed: - CVE-2019-12450: Fixed an improper file permission when copy operation takes place (bsc#1137001). - CVE-2018-16428: Avoid a NULL pointer dereference (bsc#1107121). - CVE-2018-16429: Fixed out-of-bounds read vulnerability ing_markup_parse_context_parse() (bsc#1107116). - Some exploitable parser bugs in GVariant and GDBus subsystems were fixed (bsc#1111499). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-1596=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2019-1596=1 Package List: - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): glib2-debugsource-2.38.2-7.9.2 glib2-tools-2.38.2-7.9.2 glib2-tools-debuginfo-2.38.2-7.9.2 libgio-2_0-0-2.38.2-7.9.2 libgio-2_0-0-debuginfo-2.38.2-7.9.2 libglib-2_0-0-2.38.2-7.9.2 libglib-2_0-0-debuginfo-2.38.2-7.9.2 libgmodule-2_0-0-2.38.2-7.9.2 libgmodule-2_0-0-debuginfo-2.38.2-7.9.2 libgobject-2_0-0-2.38.2-7.9.2 libgobject-2_0-0-debuginfo-2.38.2-7.9.2 libgthread-2_0-0-2.38.2-7.9.2 libgthread-2_0-0-debuginfo-2.38.2-7.9.2 - SUSE Linux Enterprise Server 12-SP1-LTSS (s390x x86_64): libgio-2_0-0-32bit-2.38.2-7.9.2 libgio-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libglib-2_0-0-32bit-2.38.2-7.9.2 libglib-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libgmodule-2_0-0-32bit-2.38.2-7.9.2 libgmodule-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libgobject-2_0-0-32bit-2.38.2-7.9.2 libgobject-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libgthread-2_0-0-32bit-2.38.2-7.9.2 libgthread-2_0-0-debuginfo-32bit-2.38.2-7.9.2 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): glib2-lang-2.38.2-7.9.2 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): glib2-debugsource-2.38.2-7.9.2 glib2-tools-2.38.2-7.9.2 glib2-tools-debuginfo-2.38.2-7.9.2 libgio-2_0-0-2.38.2-7.9.2 libgio-2_0-0-debuginfo-2.38.2-7.9.2 libglib-2_0-0-2.38.2-7.9.2 libglib-2_0-0-debuginfo-2.38.2-7.9.2 libgmodule-2_0-0-2.38.2-7.9.2 libgmodule-2_0-0-debuginfo-2.38.2-7.9.2 libgobject-2_0-0-2.38.2-7.9.2 libgobject-2_0-0-debuginfo-2.38.2-7.9.2 libgthread-2_0-0-2.38.2-7.9.2 libgthread-2_0-0-debuginfo-2.38.2-7.9.2 - SUSE Linux Enterprise Server 12-LTSS (s390x x86_64): libgio-2_0-0-32bit-2.38.2-7.9.2 libgio-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libglib-2_0-0-32bit-2.38.2-7.9.2 libglib-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libgmodule-2_0-0-32bit-2.38.2-7.9.2 libgmodule-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libgobject-2_0-0-32bit-2.38.2-7.9.2 libgobject-2_0-0-debuginfo-32bit-2.38.2-7.9.2 libgthread-2_0-0-32bit-2.38.2-7.9.2 libgthread-2_0-0-debuginfo-32bit-2.38.2-7.9.2 - SUSE Linux Enterprise Server 12-LTSS (noarch): glib2-lang-2.38.2-7.9.2 References: https://www.suse.com/security/cve/CVE-2018-16428.html https://www.suse.com/security/cve/CVE-2018-16429.html https://www.suse.com/security/cve/CVE-2019-12450.html https://bugzilla.suse.com/1107116 https://bugzilla.suse.com/1107121 https://bugzilla.suse.com/1111499 https://bugzilla.suse.com/1137001 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.