Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#1219023 * bsc#1220503 Cross-References: * CVE-2024-21733 . # Security update for tomcat Announcement ID: SUSE-SU-2024:0829-1 Rating: important References: * bsc#1219023 * bsc#1220503 Cross-References: * CVE-2024-21733 CVSS scores: * CVE-2024-21733 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-21733 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2024-21733: Fixed leaking of unrelated request bodies in default error page (bsc#1219023, bsc#1220503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-829=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-829=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-829=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * tomcat-lib-9.0.36-3.121.1 * tomcat-docs-webapp-9.0.36-3.121.1 * tomcat-webapps-9.0.36-3.121.1 * tomcat-javadoc-9.0.36-3.121.1 * tomcat-9.0.36-3.121.1 * tomcat-admin-webapps-9.0.36-3.121.1 * tomcat-el-3_0-api-9.0.36-3.121.1 * tomcat-servlet-4_0-api-9.0.36-3.121.1 * tomcat-jsp-2_3-api-9.0.36-3.121.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * tomcat-lib-9.0.36-3.121.1 * tomcat-docs-webapp-9.0.36-3.121.1 * tomcat-webapps-9.0.36-3.121.1 *tomcat-javadoc-9.0.36-3.121.1 * tomcat-9.0.36-3.121.1 * tomcat-admin-webapps-9.0.36-3.121.1 * tomcat-el-3_0-api-9.0.36-3.121.1 * tomcat-servlet-4_0-api-9.0.36-3.121.1 * tomcat-jsp-2_3-api-9.0.36-3.121.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * tomcat-lib-9.0.36-3.121.1 * tomcat-docs-webapp-9.0.36-3.121.1 * tomcat-webapps-9.0.36-3.121.1 * tomcat-javadoc-9.0.36-3.121.1 * tomcat-9.0.36-3.121.1 * tomcat-admin-webapps-9.0.36-3.121.1 * tomcat-el-3_0-api-9.0.36-3.121.1 * tomcat-servlet-4_0-api-9.0.36-3.121.1 * tomcat-jsp-2_3-api-9.0.36-3.121.1 ## References: * https://www.suse.com/security/cve/CVE-2024-21733.html * https://bugzilla.suse.com/show_bug.cgi?id=1219023 * https://bugzilla.suse.com/show_bug.cgi?id=1220503 . SUSE has released a significant update for tomcat that fixes a critical vulnerability discovered in the standard error page for servers.. SUSE Tomcat Update, Tomcat Security Fix, Important SUSE Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for helm-mirror ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1888-1 Rating: moderate References: #1156646 #1197728 Cross-References: CVE-2019-18658 CVSS scores: CVE-2019-18658 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-18658 (SUSE): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Containers 15-SP3 SUSE Linux Enterprise Module for Containers 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for helm-mirror fixes the following issues: - Updated to version 0.3.1: - CVE-2019-18658: Fixed a potential symbolic link issue in helm that could be used to leak sensitive files (bsc#1156646). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1888=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1888=1 - SUSE Linux Enterprise Module for Containers 15-SP4: zypper in -t patch SUSE-SLE-Module-Containers-15-SP4-2022-1888=1 - SUSE Linux Enterprise Module for Containers 15-SP3: zypper in -t patch SUSE-SLE-Module-Containers-15-SP3-2022-1888=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 - SUSE Linux Enterprise Module for Containers 15-SP4 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 - SUSE Linux Enterprise Module for Containers 15-SP3 (aarch64 ppc64le s390x x86_64): helm-mirror-0.3.1-150000.1.13.1 helm-mirror-debuginfo-0.3.1-150000.1.13.1 References: https://www.suse.com/security/cve/CVE-2019-18658.html https://bugzilla.suse.com/1156646 https://bugzilla.suse.com/1197728 . SUSE Security Update for helm-mirror tackles a moderate vulnerability related to symbolic links, reinforcing overall system reliability.. helm mirror update, SUSE security patch, Linux server security. . Severity: Important. LinuxSecurity.com Team
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Such a user could be a customer inserting data via a control panel, or somebody with access to the REST API. Crafted records cannot be inserted via AXFR (CVE-2020-17482). . MGASA-2020-0375 - Updated pdns packages fix security vulnerability Publication date: 27 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0375.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-17482 An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Such a user could be a customer inserting data via a control panel, or somebody with access to the REST API. Crafted records cannot be inserted via AXFR (CVE-2020-17482). The pdns package has been updated to versoin 4.1.14, fixing this issue and several other bugs. See the upstream changelog for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27310 - https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.14 - https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-05.html - https://www.cve.org/CVERecord?id=CVE-2020-17482 SRPMS: - 7/core/pdns-4.1.14-1.mga7 . Mageia 7 pdns patch addresses memory leak for trusted users; bolster system protection.. PowerDNS Security, Memory Leak Issue, Mageia Updates, pdns Vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.