An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for ffmpeg-4 ______________________________________________________________________________ Announcement ID: SUSE-SU-2023:0008-1 Rating: moderate References: #1206442 Cross-References: CVE-2022-3109 CVSS scores: CVE-2022-3109 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-3109 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Workstation Extension 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for ffmpeg-4 fixes the following issues: - CVE-2022-3109: Fixed null pointer dereference in vp3_decode_frame() (bsc#1206442). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2023-8=1 - SUSE Linux Enterprise Workstation Extension 15-SP4: zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2023-8=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4: zypper in -tpatch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-8=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-8=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): ffmpeg-4-4.4-150400.3.8.1 ffmpeg-4-debuginfo-4.4-150400.3.8.1 ffmpeg-4-debugsource-4.4-150400.3.8.1 ffmpeg-4-libavcodec-devel-4.4-150400.3.8.1 ffmpeg-4-libavdevice-devel-4.4-150400.3.8.1 ffmpeg-4-libavfilter-devel-4.4-150400.3.8.1 ffmpeg-4-libavformat-devel-4.4-150400.3.8.1 ffmpeg-4-libavresample-devel-4.4-150400.3.8.1 ffmpeg-4-libavutil-devel-4.4-150400.3.8.1 ffmpeg-4-libpostproc-devel-4.4-150400.3.8.1 ffmpeg-4-libswresample-devel-4.4-150400.3.8.1 ffmpeg-4-libswscale-devel-4.4-150400.3.8.1 ffmpeg-4-private-devel-4.4-150400.3.8.1 libavcodec58_134-4.4-150400.3.8.1 libavcodec58_134-debuginfo-4.4-150400.3.8.1 libavdevice58_13-4.4-150400.3.8.1 libavdevice58_13-debuginfo-4.4-150400.3.8.1 libavfilter7_110-4.4-150400.3.8.1 libavfilter7_110-debuginfo-4.4-150400.3.8.1 libavformat58_76-4.4-150400.3.8.1 libavformat58_76-debuginfo-4.4-150400.3.8.1 libavresample4_0-4.4-150400.3.8.1 libavresample4_0-debuginfo-4.4-150400.3.8.1 libavutil56_70-4.4-150400.3.8.1 libavutil56_70-debuginfo-4.4-150400.3.8.1 libpostproc55_9-4.4-150400.3.8.1 libpostproc55_9-debuginfo-4.4-150400.3.8.1 libswresample3_9-4.4-150400.3.8.1 libswresample3_9-debuginfo-4.4-150400.3.8.1 libswscale5_9-4.4-150400.3.8.1 libswscale5_9-debuginfo-4.4-150400.3.8.1 - openSUSE Leap 15.4 (x86_64): libavcodec58_134-32bit-4.4-150400.3.8.1 libavcodec58_134-32bit-debuginfo-4.4-150400.3.8.1 libavdevice58_13-32bit-4.4-150400.3.8.1 libavdevice58_13-32bit-debuginfo-4.4-150400.3.8.1 libavfilter7_110-32bit-4.4-150400.3.8.1 libavfilter7_110-32bit-debuginfo-4.4-150400.3.8.1 libavformat58_76-32bit-4.4-150400.3.8.1 libavformat58_76-32bit-debuginfo-4.4-150400.3.8.1 libavresample4_0-32bit-4.4-150400.3.8.1 libavresample4_0-32bit-debuginfo-4.4-150400.3.8.1 libavutil56_70-32bit-4.4-150400.3.8.1 libavutil56_70-32bit-debuginfo-4.4-150400.3.8.1 libpostproc55_9-32bit-4.4-150400.3.8.1 libpostproc55_9-32bit-debuginfo-4.4-150400.3.8.1 libswresample3_9-32bit-4.4-150400.3.8.1 libswresample3_9-32bit-debuginfo-4.4-150400.3.8.1 libswscale5_9-32bit-4.4-150400.3.8.1 libswscale5_9-32bit-debuginfo-4.4-150400.3.8.1 - SUSE Linux Enterprise Workstation Extension 15-SP4 (x86_64): ffmpeg-4-debuginfo-4.4-150400.3.8.1 ffmpeg-4-debugsource-4.4-150400.3.8.1 libavformat58_76-4.4-150400.3.8.1 libavformat58_76-debuginfo-4.4-150400.3.8.1 libswscale5_9-4.4-150400.3.8.1 libswscale5_9-debuginfo-4.4-150400.3.8.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (aarch64 ppc64le s390x x86_64): ffmpeg-4-debuginfo-4.4-150400.3.8.1 ffmpeg-4-debugsource-4.4-150400.3.8.1 libavformat58_76-4.4-150400.3.8.1 libavformat58_76-debuginfo-4.4-150400.3.8.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (aarch64 ppc64le s390x x86_64): ffmpeg-4-debuginfo-4.4-150400.3.8.1 ffmpeg-4-debugsource-4.4-150400.3.8.1 libavcodec58_134-4.4-150400.3.8.1 libavcodec58_134-debuginfo-4.4-150400.3.8.1 libavutil56_70-4.4-150400.3.8.1 libavutil56_70-debuginfo-4.4-150400.3.8.1 libswresample3_9-4.4-150400.3.8.1 libswresample3_9-debuginfo-4.4-150400.3.8.1 References: https://www.suse.com/security/cve/CVE-2022-3109.html https://bugzilla.suse.com/1206442 . SUSE has published a patch that resolves a critical null reference bug in ffmpeg-4, aiming to bolster the security and reliability of systems.. SUSE Linux, ffmpeg security, package update, software vulnerability, system patch. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2021-9619 https://linux.oracle.com/errata/ELSA-2021-9619.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: httpd-2.4.6-97.0.5.el7_9.2.aarch64.rpm httpd-devel-2.4.6-97.0.5.el7_9.2.aarch64.rpm httpd-manual-2.4.6-97.0.5.el7_9.2.noarch.rpm httpd-tools-2.4.6-97.0.5.el7_9.2.aarch64.rpm mod_session-2.4.6-97.0.5.el7_9.2.aarch64.rpm mod_ssl-2.4.6-97.0.5.el7_9.2.aarch64.rpm mod_ldap-2.4.6-97.0.5.el7_9.2.aarch64.rpm mod_proxy_html-2.4.6-97.0.5.el7_9.2.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/httpd-2.4.6-97.0.5.el7_9.2.src.rpm Related CVEs: CVE-2021-34798 CVE-2021-39275 Description of changes: [2.4.6-97.0.5.2] - scoreboard: fix null pointer deference [Orabug: 33561206][CVE-2021-34798] - fix ap_escape_quote logic [Orabug: 33617690][CVE-2021-39275] _______________________________________________ El-errata mailing list
The container suse/sles12sp5 was updated. The following patches have been included in this update: . SUSE Container Update Advisory: suse/sles12sp5 -----------------------------------------------------------------Container Advisory ID : SUSE-CU-2020:767-1 Container Tags : suse/sles12sp5:6.5.105 , suse/sles12sp5:latest Container Release : 6.5.105 Severity : important Type : security References : 1179491 CVE-2020-1971 -----------------------------------------------------------------The container suse/sles12sp5 was updated. The following patches have been included in this update: -----------------------------------------------------------------Advisory ID: SUSE-SU-2020:3732-1 Released: Wed Dec 9 18:18:03 2020 Summary: Security update for openssl-1_0_0 Type: security Severity: important References: 1179491,CVE-2020-1971 This update for openssl-1_0_0 fixes the following issues: - CVE-2020-1971: Fixed a null pointer dereference in EDIPARTYNAME (bsc#1179491). . SUSE Container Patch Notification for suse/sles12sp5 tackling critical vulnerabilities. Contains specifics on updates and fixes implemented.. SUSE Container, Security Update, OpenSSL Fix, Important Advisory. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.