The container suse/pcp was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3101-1 Container Tags : suse/pcp:5 , suse/pcp:5-17.120 , suse/pcp:5.2 , suse/pcp:5.2-17.120 , suse/pcp:5.2.5 , suse/pcp:5.2.5-17.120 Container Release : 17.120 Severity : important Type : security References : 1195517 1196861 1204505 1205145 1214052 1214052 1214768 CVE-2023-39615 CVE-2023-4039 CVE-2023-4039 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3661-1 Released: Mon Sep 18 21:44:09 2023 Summary: Security update for gcc12 Type: security Severity: important References: 1214052,CVE-2023-4039 This update for gcc12 fixes the following issues: - CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3686-1 Released: Tue Sep 19 17:23:03 2023 Summary: Security update for gcc7 Type: security Severity: important References: 1195517,1196861,1204505,1205145,1214052,CVE-2023-4039 This update for gcc7 fixes the following issues: Security issue fixed: - CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052). Other fixes: - Fixed KASAN kernel compile. [bsc#1205145] - Fixed ICE with C++17 code as reported in [bsc#1204505] - Fixed altivec.h redefining bool in C++ which makes bool unusable (bsc#1195517): - Adjust gnats idea of the target, fixing the build of gprbuild. [bsc#1196861] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3699-1 Released: Wed Sep 20 11:02:502023 Summary: Security update for libxml2 Type: security Severity: important References: 1214768,CVE-2023-39615 This update for libxml2 fixes the following issues: - CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768). The following package changes have been done: - libgcc_s1-12.3.0+git1204-150000.1.16.1 updated - libstdc++6-12.3.0+git1204-150000.1.16.1 updated - libxml2-2-2.9.14-150400.5.22.1 updated - cpp7-7.5.0+r278197-150000.4.35.1 updated - container:bci-bci-init-15.4-15.4-29.57 updated . Essential patches for suse/pcp, tackling significant vulnerabilities in gcc and libxml2. Ensure your system's security!. suse container updates, suse security, pcp patches, security advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for pcp ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1873-1 Rating: moderate References: #1171883 Cross-References: CVE-2020-8025 CVSS scores: CVE-2020-8025 (SUSE): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for pcp fixes the following issues: - CVE-2020-8025: Fixed outdated entries in permissions profiles for /var/lib/pcp/tmp/* (bsc#1171883). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-1873=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libpcp-devel-3.11.9-6.17.1 libpcp3-3.11.9-6.17.1 libpcp3-debuginfo-3.11.9-6.17.1 libpcp_gui2-3.11.9-6.17.1 libpcp_gui2-debuginfo-3.11.9-6.17.1 libpcp_import1-3.11.9-6.17.1 libpcp_import1-debuginfo-3.11.9-6.17.1 libpcp_mmv1-3.11.9-6.17.1 libpcp_mmv1-debuginfo-3.11.9-6.17.1 libpcp_trace2-3.11.9-6.17.1 libpcp_trace2-debuginfo-3.11.9-6.17.1 libpcp_web1-3.11.9-6.17.1 libpcp_web1-debuginfo-3.11.9-6.17.1 pcp-3.11.9-6.17.1 pcp-conf-3.11.9-6.17.1 pcp-debuginfo-3.11.9-6.17.1 pcp-debugsource-3.11.9-6.17.1 pcp-devel-3.11.9-6.17.1 pcp-devel-debuginfo-3.11.9-6.17.1 pcp-export-pcp2graphite-3.11.9-6.17.1 pcp-export-pcp2influxdb-3.11.9-6.17.1 pcp-export-zabbix-agent-3.11.9-6.17.1 pcp-export-zabbix-agent-debuginfo-3.11.9-6.17.1 pcp-gui-3.11.9-6.17.1 pcp-gui-debuginfo-3.11.9-6.17.1 pcp-import-collectl2pcp-3.11.9-6.17.1 pcp-import-collectl2pcp-debuginfo-3.11.9-6.17.1 pcp-import-ganglia2pcp-3.11.9-6.17.1 pcp-import-iostat2pcp-3.11.9-6.17.1 pcp-import-mrtg2pcp-3.11.9-6.17.1 pcp-import-sar2pcp-3.11.9-6.17.1 pcp-manager-3.11.9-6.17.1 pcp-manager-debuginfo-3.11.9-6.17.1 pcp-pmda-activemq-3.11.9-6.17.1 pcp-pmda-apache-3.11.9-6.17.1 pcp-pmda-apache-debuginfo-3.11.9-6.17.1 pcp-pmda-bash-3.11.9-6.17.1 pcp-pmda-bash-debuginfo-3.11.9-6.17.1 pcp-pmda-bind2-3.11.9-6.17.1 pcp-pmda-bonding-3.11.9-6.17.1 pcp-pmda-cifs-3.11.9-6.17.1 pcp-pmda-cifs-debuginfo-3.11.9-6.17.1 pcp-pmda-cisco-3.11.9-6.17.1 pcp-pmda-cisco-debuginfo-3.11.9-6.17.1 pcp-pmda-dbping-3.11.9-6.17.1 pcp-pmda-dm-3.11.9-6.17.1 pcp-pmda-dm-debuginfo-3.11.9-6.17.1 pcp-pmda-docker-3.11.9-6.17.1 pcp-pmda-docker-debuginfo-3.11.9-6.17.1 pcp-pmda-ds389-3.11.9-6.17.1 pcp-pmda-ds389log-3.11.9-6.17.1 pcp-pmda-elasticsearch-3.11.9-6.17.1 pcp-pmda-gfs2-3.11.9-6.17.1 pcp-pmda-gfs2-debuginfo-3.11.9-6.17.1 pcp-pmda-gluster-3.11.9-6.17.1 pcp-pmda-gpfs-3.11.9-6.17.1 pcp-pmda-gpsd-3.11.9-6.17.1 pcp-pmda-kvm-3.11.9-6.17.1 pcp-pmda-libvirt-3.11.9-6.17.1 pcp-pmda-lio-3.11.9-6.17.1 pcp-pmda-lmsensors-3.11.9-6.17.1 pcp-pmda-lmsensors-debuginfo-3.11.9-6.17.1 pcp-pmda-logger-3.11.9-6.17.1 pcp-pmda-logger-debuginfo-3.11.9-6.17.1 pcp-pmda-lustre-3.11.9-6.17.1 pcp-pmda-lustrecomm-3.11.9-6.17.1 pcp-pmda-lustrecomm-debuginfo-3.11.9-6.17.1 pcp-pmda-mailq-3.11.9-6.17.1 pcp-pmda-mailq-debuginfo-3.11.9-6.17.1 pcp-pmda-memcache-3.11.9-6.17.1 pcp-pmda-mic-3.11.9-6.17.1 pcp-pmda-mounts-3.11.9-6.17.1 pcp-pmda-mounts-debuginfo-3.11.9-6.17.1 pcp-pmda-mysql-3.11.9-6.17.1 pcp-pmda-named-3.11.9-6.17.1 pcp-pmda-netfilter-3.11.9-6.17.1 pcp-pmda-news-3.11.9-6.17.1 pcp-pmda-nfsclient-3.11.9-6.17.1 pcp-pmda-nginx-3.11.9-6.17.1 pcp-pmda-nutcracker-3.11.9-6.17.1 pcp-pmda-nvidia-gpu-3.11.9-6.17.1 pcp-pmda-nvidia-gpu-debuginfo-3.11.9-6.17.1 pcp-pmda-oracle-3.11.9-6.17.1 pcp-pmda-pdns-3.11.9-6.17.1 pcp-pmda-postfix-3.11.9-6.17.1 pcp-pmda-redis-3.11.9-6.17.1 pcp-pmda-roomtemp-3.11.9-6.17.1 pcp-pmda-roomtemp-debuginfo-3.11.9-6.17.1 pcp-pmda-rpm-3.11.9-6.17.1 pcp-pmda-rpm-debuginfo-3.11.9-6.17.1 pcp-pmda-rsyslog-3.11.9-6.17.1 pcp-pmda-samba-3.11.9-6.17.1 pcp-pmda-sendmail-3.11.9-6.17.1 pcp-pmda-sendmail-debuginfo-3.11.9-6.17.1 pcp-pmda-shping-3.11.9-6.17.1 pcp-pmda-shping-debuginfo-3.11.9-6.17.1 pcp-pmda-slurm-3.11.9-6.17.1 pcp-pmda-snmp-3.11.9-6.17.1 pcp-pmda-summary-3.11.9-6.17.1 pcp-pmda-summary-debuginfo-3.11.9-6.17.1 pcp-pmda-systemd-3.11.9-6.17.1 pcp-pmda-systemd-debuginfo-3.11.9-6.17.1 pcp-pmda-trace-3.11.9-6.17.1 pcp-pmda-trace-debuginfo-3.11.9-6.17.1 pcp-pmda-unbound-3.11.9-6.17.1 pcp-pmda-vmware-3.11.9-6.17.1 pcp-pmda-weblog-3.11.9-6.17.1 pcp-pmda-weblog-debuginfo-3.11.9-6.17.1 pcp-pmda-zimbra-3.11.9-6.17.1 pcp-pmda-zswap-3.11.9-6.17.1 pcp-system-tools-3.11.9-6.17.1 pcp-webapi-3.11.9-6.17.1 pcp-webapi-debuginfo-3.11.9-6.17.1 perl-PCP-LogImport-3.11.9-6.17.1 perl-PCP-LogImport-debuginfo-3.11.9-6.17.1 perl-PCP-LogSummary-3.11.9-6.17.1 perl-PCP-MMV-3.11.9-6.17.1 perl-PCP-MMV-debuginfo-3.11.9-6.17.1 perl-PCP-PMDA-3.11.9-6.17.1 perl-PCP-PMDA-debuginfo-3.11.9-6.17.1 python-pcp-3.11.9-6.17.1 python-pcp-debuginfo-3.11.9-6.17.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le x86_64): pcp-pmda-infiniband-3.11.9-6.17.1 pcp-pmda-infiniband-debuginfo-3.11.9-6.17.1 pcp-pmda-perfevent-3.11.9-6.17.1 pcp-pmda-perfevent-debuginfo-3.11.9-6.17.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (noarch): pcp-doc-3.11.9-6.17.1 References: https://www.suse.com/security/cve/CVE-2020-8025.html https://bugzilla.suse.com/1171883 . SUSE Security Advisory SUSE-SU-2022:1874-1: pcp update addresses a low severity vulnerability concerning access control. SUSE Security Update, Linux Enterprise Patch, pcp Fix, Software Update Instructions. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.