Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Update to gstreamer-1.24.10, fixes multiple CVEs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0a5722a980 2024-12-22 02:00:45.594041+00:00 -------------------------------------------------------------------------------- Name : mingw-directxmath Product : Fedora 41 Version : 3.20 Release : 1.fc41 URL : https://github.com/microsoft/DirectXMath Summary : MinGW Windows directxmath library Description : MinGW Windows directxmath library. -------------------------------------------------------------------------------- Update Information: Update to gstreamer-1.24.10, fixes multiple CVEs. -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 17 2024 Sandro Mani - 3.20-1 - Update to 3.20 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2331794 - CVE-2024-47542 mingw-gstreamer1-plugins-base: ID3v2 parser out-of-bounds read and NULL-pointer dereference [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331794 [ 2 ] Bug #2331798 - CVE-2024-47540 mingw-gstreamer1-plugins-good: uninitialized stack memory in Matroska/WebM demuxer [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331798 [ 3 ] Bug #2331815 - CVE-2024-47537 mingw-gstreamer1-plugins-good: OOB-write in isomp4/qtdemux.c [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331815 [ 4 ] Bug #2331819 - CVE-2024-47539 mingw-gstreamer1-plugins-good: OOB-write in convert_to_s334_1a [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331819 [ 5 ] Bug #2331829 - CVE-2024-47538 mingw-gstreamer1-plugins-base: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331829 [ 6 ] Bug #2331865 - CVE-2024-47615 mingw-gstreamer1-plugins-base: out-of-bounds write in Ogg demuxer[fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331865 [ 7 ] Bug #2331875 - CVE-2024-47607 mingw-gstreamer1-plugins-base: stack-buffer overflow in gst_opus_dec_parse_header [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331875 [ 8 ] Bug #2331890 - CVE-2024-47606 mingw-gstreamer1-plugins-good: integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331890 [ 9 ] Bug #2331894 - CVE-2024-47543 mingw-gstreamer1-plugins-good: OOB-read in qtdemux_parse_container [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331894 [ 10 ] Bug #2331899 - CVE-2024-47541 mingw-gstreamer1-plugins-base: GStreamer has an out-of-bounds write in SSA subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331899 [ 11 ] Bug #2331903 - CVE-2024-47600 mingw-gstreamer1-plugins-base: GStreamer has an OOB-read in format_channel_mask [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331903 [ 12 ] Bug #2331907 - CVE-2024-47774 mingw-gstreamer1-plugins-good: GStreamer has an OOB-read in gst_avi_subtitle_parse_gab2_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331907 [ 13 ] Bug #2332091 - CVE-2024-47777 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_smpl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332091 [ 14 ] Bug #2332093 - CVE-2024-47835 mingw-gstreamer1-plugins-base: NULL-pointer dereference in LRC subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332093 [ 15 ] Bug #2332096 - CVE-2024-47778 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_adtl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332096 [ 16 ] Bug #2332098 - CVE-2024-47775 mingw-gstreamer1-plugins-good: OOB-read in parse_ds64 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332098 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0a5722a980' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1228924 Cross-References: * CVE-2024-7006 . # Security update for tiff Announcement ID: SUSE-SU-2024:3115-1 Rating: moderate References: * bsc#1228924 Cross-References: * CVE-2024-7006 CVSS scores: * CVE-2024-7006 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7006 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP5 * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for tiff fixes the following issues: * CVE-2024-7006: Fixed null pointer dereference in tif_dirinfo.c (bsc#1228924) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.5 zypper in -t patch openSUSE-Leap-Micro-5.5-2024-3115=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3115=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patchSUSE-SLE-Micro-5.3-2024-3115=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-3115=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-3115=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-3115=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-3115=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-3115=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-3115=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-3115=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-3115=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-3115=1 ## Package List: * openSUSE Leap Micro 5.5 (aarch64 s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * openSUSE Leap 15.5 (x86_64) * libtiff-devel-32bit-4.0.9-150000.45.47.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.47.1 * libtiff5-32bit-4.0.9-150000.45.47.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * tiff-debuginfo-4.0.9-150000.45.47.1 * libtiff-devel-4.0.9-150000.45.47.1 * tiff-4.0.9-150000.45.47.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 *libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * tiff-debuginfo-4.0.9-150000.45.47.1 * libtiff-devel-4.0.9-150000.45.47.1 * Basesystem Module 15-SP5 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.47.1 * libtiff5-32bit-4.0.9-150000.45.47.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * Basesystem Module 15-SP6 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.47.1 * libtiff5-32bit-4.0.9-150000.45.47.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * tiff-4.0.9-150000.45.47.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) *tiff-debuginfo-4.0.9-150000.45.47.1 * tiff-debugsource-4.0.9-150000.45.47.1 * libtiff5-debuginfo-4.0.9-150000.45.47.1 * libtiff5-4.0.9-150000.45.47.1 ## References: * https://www.suse.com/security/cve/CVE-2024-7006.html * https://bugzilla.suse.com/show_bug.cgi?id=1228924 . SUSE has released a balanced update for tiff concerning CVE-2024-7006, complete with guidelines for installation and applying patches.. TIFF Security Update, SUSE Fix, Software Patch, Linux Security Advisory. . LinuxSecurity.com Team
A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/Ztring.cpp. The manipulation of the argument Value leads to unchecked return value to null pointer dereference. (CVE-2020-36646) . MGASA-2023-0046 - Updated libzen packages fix security vulnerability Publication date: 14 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0046.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-36646 A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/Ztring.cpp. The manipulation of the argument Value leads to unchecked return value to null pointer dereference. (CVE-2020-36646) References: - https://bugs.mageia.org/show_bug.cgi?id=31492 - https://lists.debian.org/debian-lts-announce/2023/01/msg00029.html - https://www.cve.org/CVERecord?id=CVE-2020-36646 SRPMS: - 8/core/libzen-0.4.38-1.1.mga8 . A significant security bulletin has been issued for Mageia, highlighting a severe vulnerability within libzen that compromises local date interpretation. Dive into the patch!. Mageia Libzen Security Update, MediaArea Vulnerability, Null Pointer Dereference, Security Issue Mitigation. . Severity: Critical. LinuxSecurity.com Team
Fix for CVE-2022-36227. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e15be0091f 2022-12-19 01:14:07.970062 --------------------------------------------------------------------------------Name : libarchive Product : Fedora 37 Version : 3.6.1 Release : 3.fc37 URL : https://www.libarchive.org/ Summary : A library for handling streaming archive formats Description : Libarchive is a programming library that can create and read several different streaming archive formats, including most popular tar variants, several cpio formats, and both BSD and GNU ar variants. It can also write shar archives and read ISO9660 CDROM images and ZIP archives. --------------------------------------------------------------------------------Update Information: Fix for CVE-2022-36227 --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Lukas Javorsky - 3.6.1-3 - Resolves: CVE-2022-36227 --------------------------------------------------------------------------------References: [ 1 ] Bug #2144974 - CVE-2022-36227 libarchive: Null pointer dereference in archive_write.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2144974 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e15be0091f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Null pointer dereference in wvunpack (CVE-2022-2476) References: - https://bugs.mageia.org/show_bug.cgi?id=30713 - https://lists.suse.com/pipermail/sle-security-updates/2022-August/011810.html . MGASA-2022-0291 - Updated wavpack packages fix security vulnerability Publication date: 20 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0291.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2476 Null pointer dereference in wvunpack (CVE-2022-2476) References: - https://bugs.mageia.org/show_bug.cgi?id=30713 - https://lists.suse.com/pipermail/sle-security-updates/2022-August/011810.html - - https://www.cve.org/CVERecord?id=CVE-2022-2476 SRPMS: - 8/core/wavpack-5.5.0-1.mga8 . The latest wavpack updates for Mageia 8 resolve a null pointer dereference issue; this is a significant security notice MGASA-2022-0291.. wavpack update, mageia security, package vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gnutls ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0717-1 Rating: moderate References: #1196167 Cross-References: CVE-2021-4209 CVSS scores: CVE-2021-4209 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Micro 5.0 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Realtime Extension 15-SP2 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gnutls fixes the following issues: - CVE-2021-4209: Fixed null pointer dereference in MD_UPDATE (bsc#1196167). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Realtime Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-RT-15-SP2-2022-717=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-717=1 - SUSE Linux Enterprise Micro 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-717=1 - SUSE Linux Enterprise Micro 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2022-717=1 Package List: - SUSE Linux EnterpriseRealtime Extension 15-SP2 (x86_64): gnutls-3.6.7-14.16.1 gnutls-debuginfo-3.6.7-14.16.1 gnutls-debugsource-3.6.7-14.16.1 libgnutls-devel-3.6.7-14.16.1 libgnutls30-3.6.7-14.16.1 libgnutls30-32bit-3.6.7-14.16.1 libgnutls30-32bit-debuginfo-3.6.7-14.16.1 libgnutls30-debuginfo-3.6.7-14.16.1 libgnutls30-hmac-3.6.7-14.16.1 libgnutls30-hmac-32bit-3.6.7-14.16.1 libgnutlsxx-devel-3.6.7-14.16.1 libgnutlsxx28-3.6.7-14.16.1 libgnutlsxx28-debuginfo-3.6.7-14.16.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): gnutls-3.6.7-14.16.1 gnutls-debuginfo-3.6.7-14.16.1 gnutls-debugsource-3.6.7-14.16.1 libgnutls-devel-3.6.7-14.16.1 libgnutls30-3.6.7-14.16.1 libgnutls30-debuginfo-3.6.7-14.16.1 libgnutls30-hmac-3.6.7-14.16.1 libgnutlsxx-devel-3.6.7-14.16.1 libgnutlsxx28-3.6.7-14.16.1 libgnutlsxx28-debuginfo-3.6.7-14.16.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (x86_64): libgnutls30-32bit-3.6.7-14.16.1 libgnutls30-32bit-debuginfo-3.6.7-14.16.1 libgnutls30-hmac-32bit-3.6.7-14.16.1 - SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64): gnutls-debuginfo-3.6.7-14.16.1 gnutls-debugsource-3.6.7-14.16.1 libgnutls30-3.6.7-14.16.1 libgnutls30-debuginfo-3.6.7-14.16.1 libgnutls30-hmac-3.6.7-14.16.1 - SUSE Linux Enterprise Micro 5.0 (aarch64 x86_64): gnutls-debuginfo-3.6.7-14.16.1 gnutls-debugsource-3.6.7-14.16.1 libgnutls30-3.6.7-14.16.1 libgnutls30-debuginfo-3.6.7-14.16.1 References: https://www.suse.com/security/cve/CVE-2021-4209.html https://bugzilla.suse.com/show_bug.cgi?id=1196167 . Notice regarding gnutls addressing a moderate security vulnerability: CVE-2021-4209 affecting SUSE Linux platforms.. GnuTLS Fixes,SUSE Security Update,Patch Instructions. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0939-1 Rating: moderate References: #1182331 #1182333 Cross-References: CVE-2021-23840 CVE-2021-23841 CVSS scores: CVE-2021-23840 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-23840 (SUSE): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H CVE-2021-23841 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-23841 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for openssl fixes the following issues: - CVE-2021-23840: Fixed an Integer overflow in CipherUpdate (bsc#1182333) - CVE-2021-23841: Fixed a Null pointer dereference in X509_issuer_and_serial_hash() (bsc#1182331) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-939=1 - SUSEOpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-939=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2021-939=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-939=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2021-939=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-939=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-939=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2021-939=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-939=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-939=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE OpenStack Cloud Crowbar 8 (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE OpenStack Cloud 8 (x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE OpenStack Cloud 8 (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE OpenStack Cloud 7 (s390xx86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE OpenStack Cloud 7 (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x x86_64): libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): openssl-doc-1.0.2j-60.66.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 - HPE Helion Openstack 8 (noarch): openssl-doc-1.0.2j-60.66.1 - HPE Helion Openstack 8 (x86_64): libopenssl-devel-1.0.2j-60.66.1 libopenssl1_0_0-1.0.2j-60.66.1 libopenssl1_0_0-32bit-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-1.0.2j-60.66.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.66.1 libopenssl1_0_0-hmac-1.0.2j-60.66.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.66.1 openssl-1.0.2j-60.66.1 openssl-debuginfo-1.0.2j-60.66.1 openssl-debugsource-1.0.2j-60.66.1 References: https://www.suse.com/security/cve/CVE-2021-23840.html https://www.suse.com/security/cve/CVE-2021-23841.html https://bugzilla.suse.com/1182331 https://bugzilla.suse.com/1182333 . Keep informed about the SUSE Security Patch for openssl addressing integer overflow and null pointer vulnerabilities with moderate risk.. SUSE OpenStack, OpenSSL Patch, Security Update, Integer Overflow, Null Pointer Fix. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for openssl1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:14667-1 Rating: moderate References: #1182331 #1182333 Cross-References: CVE-2021-23840 CVE-2021-23841 CVSS scores: CVE-2021-23840 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-23840 (SUSE): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H CVE-2021-23841 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-23841 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 11-SECURITY SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for openssl1 fixes the following issues: - CVE-2021-23840: Fixed an Integer overflow in CipherUpdate (bsc#1182333) - CVE-2021-23841: Fixed a Null pointer dereference in X509_issuer_and_serial_hash() (bsc#1182331) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SECURITY: zypper in -t patch secsp3-openssl1-14667=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-openssl1-14667=1 Package List: - SUSE Linux Enterprise Server 11-SECURITY (i586 ia64 ppc64 s390x x86_64): libopenssl1-devel-1.0.1g-0.58.33.1 libopenssl1_0_0-1.0.1g-0.58.33.1 openssl1-1.0.1g-0.58.33.1 openssl1-doc-1.0.1g-0.58.33.1 - SUSE Linux Enterprise Server 11-SECURITY (ppc64 s390x x86_64): libopenssl1_0_0-32bit-1.0.1g-0.58.33.1 - SUSE Linux Enterprise Server 11-SECURITY (ia64): libopenssl1_0_0-x86-1.0.1g-0.58.33.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): openssl1-debuginfo-1.0.1g-0.58.33.1 openssl1-debugsource-1.0.1g-0.58.33.1 References: https://www.suse.com/security/cve/CVE-2021-23840.html https://www.suse.com/security/cve/CVE-2021-23841.html https://bugzilla.suse.com/1182331 https://bugzilla.suse.com/1182333 . New update released for openssl1 to tackle vulnerabilities in SUSE Linux Enterprise Server. Discover further details.. openssl Update, SUSE Security Fix, Enterprise Server, security advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.