Moderate: python27:2.7 security and bug fix update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:7042", "synopsis": "Moderate: python27:2.7 security and bug fix update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for python-mock, module.python-sqlalchemy, python-backports-ssl_match_hostname, python-attrs, python-chardet, python2-rpm-macros, module.numpy, module.python-mock, python-pymongo, python-markupsafe, python-psycopg2, python2-six, module.python-funcsigs, module.python-pygments, module.pytz, python-coverage, module.python-chardet, module.python-pluggy, module.python-virtualenv, module.python-PyMySQL, python-PyMySQL, module.python-dns, module.python-nose, python-pysocks, python-funcsigs, scipy, module.python-pytest-mock, module.python-attrs, numpy, python-wheel, PyYAML, module.python-docs, module.python-setuptools_scm, module.python-backports-ssl_match_hostname, babel, python-idna, python2-pip, module.python-wheel, module.python-ipaddress, module.python-markupsafe, module.python-psycopg2, python-requests, module.scipy, module.PyYAML, python-nose, module.Cython, module.python-lxml, python-sqlalchemy, module.python2-pip, python-dns, pytest, module.python-backports, module.python-coverage, module.babel, python-pluggy, module.python-docutils, module.python-requests, python-pygments, module.python-pymongo, module.python2-six, module.python-pysocks, pytz, python-docs, python-backports, python-py, python-lxml, python-pytest-mock, module.pytest, python-setuptools_scm, module.python-idna, module.python-py, python-ipaddress, Cython, module.python2-rpm-macros, python-docutils.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing. The python27 packages providea stable release of Python 2.7 with a number of additional utilities and database connectors for MySQL and PostgreSQL.\n\nSecurity Fix(es):\n\n* python-requests: Unintended leak of Proxy-Authorization header (CVE-2023-32681)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.9 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2209469", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209469", "description": ""}], "cves": [{"name": "CVE-2023-32681", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-32681", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-402"}], "references": [], "publishedAt": "2026-03-18T06:01:13.733535Z", "rpms": {"Rocky Linux 8": {"nvras": ["babel-0:2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "babel-0:2.5.1-10.module+el8.9.0+1531+a18208f5.src.rpm", "Cython-0:0.28.1-7.module+el8.9.0+1531+a18208f5.src.rpm", "Cython-debugsource-0:0.28.1-7.module+el8.9.0+1531+a18208f5.aarch64.rpm", "Cython-debugsource-0:0.28.1-7.module+el8.9.0+1531+a18208f5.x86_64.rpm", "numpy-1:1.14.2-16.module+el8.9.0+1531+a18208f5.src.rpm", "numpy-debugsource-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "numpy-debugsource-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "pytest-0:3.4.2-13.module+el8.9.0+1531+a18208f5.src.rpm", "python2-attrs-0:17.4.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-babel-0:2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-backports-0:1.0-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-backports-0:1.0-16.module+el8.9.0+1531+a18208f5.x86_64.rpm","python2-backports-ssl_match_hostname-0:3.5.0.1-12.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-bson-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-bson-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-bson-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-bson-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-chardet-0:3.0.4-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-coverage-0:4.5.1-5.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-coverage-0:4.5.1-5.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-nose-0:1.3.7-31.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-coverage-debuginfo-0:4.5.1-5.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-coverage-debuginfo-0:4.5.1-5.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-Cython-0:0.28.1-7.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-Cython-0:0.28.1-7.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-Cython-debuginfo-0:0.28.1-7.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-Cython-debuginfo-0:0.28.1-7.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-dns-0:1.15.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-docs-0:2.7.16-2.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-docs-info-0:2.7.16-2.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-docutils-0:0.14-12.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-funcsigs-0:1.0.2-13.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-idna-0:2.5-7.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-ipaddress-0:1.0.18-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-lxml-0:4.2.3-6.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-lxml-0:4.2.3-6.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-lxml-debuginfo-0:4.2.3-6.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-lxml-debuginfo-0:4.2.3-6.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-markupsafe-0:0.23-19.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-markupsafe-0:0.23-19.module+el8.9.0+1531+a18208f5.x86_64.rpm","python2-mock-0:2.0.0-13.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-numpy-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-numpy-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-numpy-debuginfo-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-numpy-debuginfo-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-numpy-doc-1:1.14.2-16.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-numpy-f2py-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-numpy-f2py-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pip-0:9.0.3-19.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pip-0:9.0.3-19.module+el8.9.0+1531+a18208f5.src.rpm", "python2-pip-wheel-0:9.0.3-19.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pluggy-0:0.6.0-8.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-psycopg2-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-debug-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-debug-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-debug-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-debug-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-tests-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-tests-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-py-0:1.5.3-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pygments-0:2.2.0-22.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pymongo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pymongo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm","python2-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pymongo-gridfs-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pymongo-gridfs-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-PyMySQL-0:0.8.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pysocks-0:1.6.8-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pytest-0:3.4.2-13.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pytest-mock-0:1.9.0-4.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pytz-0:2017.2-13.module+el8.10.0+1817+0b01df83.noarch.rpm", "python2-pyyaml-0:3.12-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pyyaml-0:3.12-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pyyaml-debuginfo-0:3.12-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pyyaml-debuginfo-0:3.12-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-requests-0:2.20.0-4.module+el8.10.0+1817+0b01df83.noarch.rpm", "python2-rpm-macros-0:3-38.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-rpm-macros-0:3-38.module+el8.9.0+1531+a18208f5.src.rpm", "python2-scipy-0:1.0.0-22.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-scipy-0:1.0.0-22.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-scipy-debuginfo-0:1.0.0-22.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-scipy-debuginfo-0:1.0.0-22.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-setuptools_scm-0:1.15.7-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-six-0:1.11.0-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-six-0:1.11.0-6.module+el8.9.0+1531+a18208f5.src.rpm", "python2-sqlalchemy-0:1.3.2-2.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-sqlalchemy-0:1.3.2-2.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-wheel-1:0.31.1-3.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-wheel-wheel-1:0.31.1-3.module+el8.9.0+1531+a18208f5.noarch.rpm", "python-attrs-0:17.4.0-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-backports-0:1.0-16.module+el8.9.0+1531+a18208f5.src.rpm","python-backports-ssl_match_hostname-0:3.5.0.1-12.module+el8.9.0+1531+a18208f5.src.rpm", "python-chardet-0:3.0.4-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-coverage-0:4.5.1-5.module+el8.10.0+1817+0b01df83.src.rpm", "python-coverage-debugsource-0:4.5.1-5.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python-coverage-debugsource-0:4.5.1-5.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-dns-0:1.15.0-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-docs-0:2.7.16-2.module+el8.9.0+1531+a18208f5.src.rpm", "python-docutils-0:0.14-12.module+el8.10.0+1592+61442852.src.rpm", "python-docutils-0:0.14-12.module+el8.10.0+1910+234ad790.src.rpm", "python-docutils-0:0.14-12.module+el8.9.0+1531+a18208f5.src.rpm", "python-funcsigs-0:1.0.2-13.module+el8.9.0+1531+a18208f5.src.rpm", "python-idna-0:2.5-7.module+el8.9.0+1531+a18208f5.src.rpm", "python-ipaddress-0:1.0.18-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-lxml-0:4.2.3-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-lxml-debugsource-0:4.2.3-6.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python-lxml-debugsource-0:4.2.3-6.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python-markupsafe-0:0.23-19.module+el8.9.0+1531+a18208f5.src.rpm", "python-mock-0:2.0.0-13.module+el8.9.0+1531+a18208f5.src.rpm", "python-nose-0:1.3.7-31.module+el8.10.0+1910+234ad790.src.rpm", "python-nose-0:1.3.7-31.module+el8.9.0+1531+a18208f5.src.rpm", "python-nose-0:1.3.7-31.module+el8.10.0+1592+61442852.src.rpm", "python-nose-docs-0:1.3.7-31.module+el8.10.0+1910+234ad790.noarch.rpm", "python-nose-docs-0:1.3.7-31.module+el8.9.0+1531+a18208f5.noarch.rpm", "python-pluggy-0:0.6.0-8.module+el8.9.0+1531+a18208f5.src.rpm", "python-psycopg2-0:2.7.5-8.module+el8.10.0+1817+0b01df83.src.rpm", "python-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-psycopg2-debugsource-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python-psycopg2-debugsource-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm","python-psycopg2-doc-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python-psycopg2-doc-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-py-0:1.5.3-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-pygments-0:2.2.0-22.module+el8.10.0+1592+61442852.src.rpm", "python-pygments-0:2.2.0-22.module+el8.10.0+1910+234ad790.src.rpm", "python-pygments-0:2.2.0-22.module+el8.9.0+1531+a18208f5.src.rpm", "python-pymongo-0:3.7.0-1.module+el8.10.0+1910+234ad790.src.rpm", "python-pymongo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.src.rpm", "python-pymongo-0:3.7.0-1.module+el8.10.0+1592+61442852.src.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.10.0+1592+61442852.aarch64.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.10.0+1910+234ad790.aarch64.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.10.0+1592+61442852.aarch64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.10.0+1910+234ad790.aarch64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python-PyMySQL-0:0.8.0-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-pysocks-0:1.6.8-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-pytest-mock-0:1.9.0-4.module+el8.9.0+1531+a18208f5.src.rpm", "python-requests-0:2.20.0-4.module+el8.10.0+1817+0b01df83.src.rpm", "python-setuptools_scm-0:1.15.7-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-sqlalchemy-0:1.3.2-2.module+el8.9.0+1531+a18208f5.src.rpm", "python-sqlalchemy-doc-0:1.3.2-2.module+el8.9.0+1531+a18208f5.noarch.rpm", "python-virtualenv-0:15.1.0-22.module+el8.10.0+1592+61442852.src.rpm", "python-wheel-1:0.31.1-3.module+el8.10.0+1592+61442852.src.rpm", "python-wheel-1:0.31.1-3.module+el8.9.0+1531+a18208f5.src.rpm", "python-wheel-1:0.31.1-3.module+el8.10.0+1910+234ad790.src.rpm","pytz-0:2017.2-13.module+el8.10.0+1817+0b01df83.src.rpm", "PyYAML-0:3.12-16.module+el8.9.0+1531+a18208f5.src.rpm", "PyYAML-debugsource-0:3.12-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "PyYAML-debugsource-0:3.12-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "scipy-0:1.0.0-22.module+el8.10.0+1817+0b01df83.src.rpm", "scipy-debugsource-0:1.0.0-22.module+el8.10.0+1817+0b01df83.aarch64.rpm", "scipy-debugsource-0:1.0.0-22.module+el8.10.0+1817+0b01df83.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate security update for python27 addressing Proxy-Authorization leak. Critical to maintain system integrity. Patching advised.. Python 2.7 security, Rocky Linux update, security advisory. . LinuxSecurity.com Team
* bsc#1219023 * bsc#1220503 Cross-References: * CVE-2024-21733 . # Security update for tomcat Announcement ID: SUSE-SU-2024:0829-1 Rating: important References: * bsc#1219023 * bsc#1220503 Cross-References: * CVE-2024-21733 CVSS scores: * CVE-2024-21733 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-21733 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2024-21733: Fixed leaking of unrelated request bodies in default error page (bsc#1219023, bsc#1220503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-829=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-829=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-829=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * tomcat-lib-9.0.36-3.121.1 * tomcat-docs-webapp-9.0.36-3.121.1 * tomcat-webapps-9.0.36-3.121.1 * tomcat-javadoc-9.0.36-3.121.1 * tomcat-9.0.36-3.121.1 * tomcat-admin-webapps-9.0.36-3.121.1 * tomcat-el-3_0-api-9.0.36-3.121.1 * tomcat-servlet-4_0-api-9.0.36-3.121.1 * tomcat-jsp-2_3-api-9.0.36-3.121.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * tomcat-lib-9.0.36-3.121.1 * tomcat-docs-webapp-9.0.36-3.121.1 * tomcat-webapps-9.0.36-3.121.1 *tomcat-javadoc-9.0.36-3.121.1 * tomcat-9.0.36-3.121.1 * tomcat-admin-webapps-9.0.36-3.121.1 * tomcat-el-3_0-api-9.0.36-3.121.1 * tomcat-servlet-4_0-api-9.0.36-3.121.1 * tomcat-jsp-2_3-api-9.0.36-3.121.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * tomcat-lib-9.0.36-3.121.1 * tomcat-docs-webapp-9.0.36-3.121.1 * tomcat-webapps-9.0.36-3.121.1 * tomcat-javadoc-9.0.36-3.121.1 * tomcat-9.0.36-3.121.1 * tomcat-admin-webapps-9.0.36-3.121.1 * tomcat-el-3_0-api-9.0.36-3.121.1 * tomcat-servlet-4_0-api-9.0.36-3.121.1 * tomcat-jsp-2_3-api-9.0.36-3.121.1 ## References: * https://www.suse.com/security/cve/CVE-2024-21733.html * https://bugzilla.suse.com/show_bug.cgi?id=1219023 * https://bugzilla.suse.com/show_bug.cgi?id=1220503 . SUSE has released a significant update for tomcat that fixes a critical vulnerability discovered in the standard error page for servers.. SUSE Tomcat Update, Tomcat Security Fix, Important SUSE Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for helm-mirror ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1888-1 Rating: moderate References: #1156646 #1197728 Cross-References: CVE-2019-18658 CVSS scores: CVE-2019-18658 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-18658 (SUSE): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Containers 15-SP3 SUSE Linux Enterprise Module for Containers 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for helm-mirror fixes the following issues: - Updated to version 0.3.1: - CVE-2019-18658: Fixed a potential symbolic link issue in helm that could be used to leak sensitive files (bsc#1156646). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1888=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1888=1 - SUSE Linux Enterprise Module for Containers 15-SP4: zypper in -t patch SUSE-SLE-Module-Containers-15-SP4-2022-1888=1 - SUSE Linux Enterprise Module for Containers 15-SP3: zypper in -t patch SUSE-SLE-Module-Containers-15-SP3-2022-1888=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 - SUSE Linux Enterprise Module for Containers 15-SP4 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 - SUSE Linux Enterprise Module for Containers 15-SP3 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 References: https://www.suse.com/security/cve/CVE-2019-18658.html https://bugzilla.suse.com/1156646 https://bugzilla.suse.com/1197728 . SUSE Security Update for helm-mirror tackles a moderate vulnerability related to symbolic links, reinforcing overall system reliability.. helm mirror update, SUSE security patch, Linux server security. . Severity: Important. LinuxSecurity.com Team
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Such a user could be a customer inserting data via a control panel, or somebody with access to the REST API. Crafted records cannot be inserted via AXFR (CVE-2020-17482). . MGASA-2020-0375 - Updated pdns packages fix security vulnerability Publication date: 27 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0375.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-17482 An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Such a user could be a customer inserting data via a control panel, or somebody with access to the REST API. Crafted records cannot be inserted via AXFR (CVE-2020-17482). The pdns package has been updated to versoin 4.1.14, fixing this issue and several other bugs. See the upstream changelog for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27310 - https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.14 - https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-05.html - https://www.cve.org/CVERecord?id=CVE-2020-17482 SRPMS: - 7/core/pdns-4.1.14-1.mga7 . Mageia 7 pdns patch addresses memory leak for trusted users; bolster system protection.. PowerDNS Security, Memory Leak Issue, Mageia Updates, pdns Vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.