The container bci/dotnet-aspnet was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2785-1 Container Tags : bci/dotnet-aspnet:5.0 , bci/dotnet-aspnet:5.0-27.28 , bci/dotnet-aspnet:5.0.17 , bci/dotnet-aspnet:5.0.17-27.28 Container Release : 27.28 Severity : important Type : security References : 1194047 1203911 1204383 1204386 CVE-2022-32221 CVE-2022-42916 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3785-1 Released: Wed Oct 26 20:20:19 2022 Summary: Security update for curl Type: security Severity: important References: 1204383,1204386,CVE-2022-32221,CVE-2022-42916 This update for curl fixes the following issues: - CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383). - CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3787-1 Released: Thu Oct 27 04:41:09 2022 Summary: Recommended update for permissions Type: recommended Severity: important References: 1194047,1203911 This update for permissions fixes the following issues: - Fix regression introduced by backport of security fix (bsc#1203911) - Add permissions for enlightenment helper on 32bit arches (bsc#1194047) The following package changes have been done: - libcurl4-7.79.1-150400.5.9.1 updated - permissions-20201225-150400.5.16.1 updated - container:sles15-image-15.0.0-27.14.8 updated . SUSE Container Security Advisory regarding bci/dotnet-aspnet addressing critical vulnerabilities in curl and other related components.. Container Security, .NET Framework Updates, SUSEAdvisory. . Severity: Important. LinuxSecurity.com Team
The container bci/rust was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2768-1 Container Tags : bci/rust:1.60 , bci/rust:1.60-6.17 Container Release : 6.17 Severity : important Type : security References : 1194047 1203911 1204383 1204386 CVE-2022-32221 CVE-2022-42916 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3785-1 Released: Wed Oct 26 20:20:19 2022 Summary: Security update for curl Type: security Severity: important References: 1204383,1204386,CVE-2022-32221,CVE-2022-42916 This update for curl fixes the following issues: - CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383). - CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3787-1 Released: Thu Oct 27 04:41:09 2022 Summary: Recommended update for permissions Type: recommended Severity: important References: 1194047,1203911 This update for permissions fixes the following issues: - Fix regression introduced by backport of security fix (bsc#1203911) - Add permissions for enlightenment helper on 32bit arches (bsc#1194047) The following package changes have been done: - libcurl4-7.79.1-150400.5.9.1 updated - permissions-20201225-150400.5.16.1 updated - container:sles15-image-15.0.0-27.14.8 updated . SUSE Container Update Notice: critical security upgrade for bci/python including http client corrections and access rights modifications.. Container Security Update,bci/rust Advisory,Curl Security Patch. . Severity: Important. LinuxSecurity.com Team
The container bci/golang was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2756-1 Container Tags : bci/golang:1.18 , bci/golang:1.18-18.13 Container Release : 18.13 Severity : important Type : security References : 1194047 1203911 1204383 1204386 CVE-2022-32221 CVE-2022-42916 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3785-1 Released: Wed Oct 26 20:20:19 2022 Summary: Security update for curl Type: security Severity: important References: 1204383,1204386,CVE-2022-32221,CVE-2022-42916 This update for curl fixes the following issues: - CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383). - CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3787-1 Released: Thu Oct 27 04:41:09 2022 Summary: Recommended update for permissions Type: recommended Severity: important References: 1194047,1203911 This update for permissions fixes the following issues: - Fix regression introduced by backport of security fix (bsc#1203911) - Add permissions for enlightenment helper on 32bit arches (bsc#1194047) The following package changes have been done: - libcurl4-7.79.1-150400.5.9.1 updated - permissions-20201225-150400.5.16.1 updated - container:sles15-image-15.0.0-27.14.8 updated . New security enhancement for bci/golang container featuring critical updates for wget and access rights.. bci/golang Update, Curl Security, Container Advisory, SUSE Update. . Severity: Important. LinuxSecurity.com Team
The container bci/dotnet-runtime was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2751-1 Container Tags : bci/dotnet-runtime:3.1 , bci/dotnet-runtime:3.1-48.11 , bci/dotnet-runtime:3.1.30 , bci/dotnet-runtime:3.1.30-48.11 Container Release : 48.11 Severity : important Type : security References : 1194047 1203911 1204383 1204386 CVE-2022-32221 CVE-2022-42916 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3785-1 Released: Wed Oct 26 20:20:19 2022 Summary: Security update for curl Type: security Severity: important References: 1204383,1204386,CVE-2022-32221,CVE-2022-42916 This update for curl fixes the following issues: - CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383). - CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3787-1 Released: Thu Oct 27 04:41:09 2022 Summary: Recommended update for permissions Type: recommended Severity: important References: 1194047,1203911 This update for permissions fixes the following issues: - Fix regression introduced by backport of security fix (bsc#1203911) - Add permissions for enlightenment helper on 32bit arches (bsc#1194047) The following package changes have been done: - libcurl4-7.79.1-150400.5.9.1 updated - permissions-20201225-150400.5.16.1 updated - container:sles15-image-15.0.0-27.14.7 updated . This release outlines critical fixes for the bci/dotnet-runtime container provided by SUSE, focusing on significant vulnerabilities.. SUSE container update, dotnet-runtimesecurity, important patches. . Severity: Important. LinuxSecurity.com Team
The container bci/dotnet-sdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2347-1 Container Tags : bci/dotnet-sdk:5.0 , bci/dotnet-sdk:5.0-35.5 , bci/dotnet-sdk:5.0.17 , bci/dotnet-sdk:5.0.17-35.5 Container Release : 35.5 Severity : moderate Type : security References : 1203018 CVE-2022-31252 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3353-1 Released: Fri Sep 23 15:23:40 2022 Summary: Security update for permissions Type: security Severity: moderate References: 1203018,CVE-2022-31252 This update for permissions fixes the following issues: - CVE-2022-31252: Fixed chkstat group controlled paths (bsc#1203018). The following package changes have been done: - permissions-20201225-150400.5.11.1 updated - container:sles15-image-15.0.0-27.11.27 updated . Minor security enhancement for bci/dotnet-runtime, resolving access control problems with key fixes implemented.. SUSE Container Update,bci/dotnet-sdk,permissions fix. . LinuxSecurity.com Team
The container bci/dotnet-runtime was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1753-1 Container Tags : bci/dotnet-runtime:6.0 , bci/dotnet-runtime:6.0-18.17 , bci/dotnet-runtime:6.0.7 , bci/dotnet-runtime:6.0.7-18.17 , bci/dotnet-runtime:latest Container Release : 18.17 Severity : important Type : security References : 1198720 1200747 1201385 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2632-1 Released: Wed Aug 3 09:51:00 2022 Summary: Security update for permissions Type: security Severity: important References: 1198720,1200747,1201385 This update for permissions fixes the following issues: * apptainer: fix starter-suid location (bsc#1198720) * static permissions: remove deprecated bind / named chroot entries (bsc#1200747) * postfix: add postlog setgid for maildrop binary (bsc#1201385) The following package changes have been done: - permissions-20201225-150400.5.8.1 updated - container:sles15-image-15.0.0-27.11.9 updated . Crucial security patch released for the bci/dotnet-runtime image targeting user access problems and security flaws.. bci/dotnet-runtime security, container permissions update, SUSE advisory. . Severity: Important. LinuxSecurity.com Team
The container bci/dotnet-sdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1750-1 Container Tags : bci/dotnet-sdk:6.0 , bci/dotnet-sdk:6.0-21.17 , bci/dotnet-sdk:6.0.7 , bci/dotnet-sdk:6.0.7-21.17 , bci/dotnet-sdk:latest Container Release : 21.17 Severity : important Type : security References : 1198720 1200747 1201385 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2632-1 Released: Wed Aug 3 09:51:00 2022 Summary: Security update for permissions Type: security Severity: important References: 1198720,1200747,1201385 This update for permissions fixes the following issues: * apptainer: fix starter-suid location (bsc#1198720) * static permissions: remove deprecated bind / named chroot entries (bsc#1200747) * postfix: add postlog setgid for maildrop binary (bsc#1201385) The following package changes have been done: - permissions-20201225-150400.5.8.1 updated - container:sles15-image-15.0.0-27.11.9 updated . Upgraded bci/dotnet-sdk environment to mitigate critical security gaps and enhance overall system integrity.. bci/dotnet-sdk, container update, permissions fix, security patch. . Severity: Important. LinuxSecurity.com Team
Remove executable permissions from scripts in /usr/shar. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-a66734e7a2 2022-01-19 02:10:14.239473 --------------------------------------------------------------------------------Name : btrbk Product : Fedora 35 Version : 0.31.3 Release : 1.fc35 URL : https://digint.ch/btrbk/ Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes Description : Backup tool for btrfs sub-volumes, using a configuration file, allows creation of backups from multiple sources to multiple destinations, with ssh and flexible retention policy support (hourly, daily, weekly, monthly) --------------------------------------------------------------------------------Update Information: Remove executable permissions from scripts in /usr/shar --------------------------------------------------------------------------------ChangeLog: * Mon Jan 10 2022 Juan Orti Alcaine - 0.31.3-1 - Version 0.31.3 (#1765928) - Remove executable permissions from scripts in /usr/share (#1994989) --------------------------------------------------------------------------------References: [ 1 ] Bug #1994989 - CVE-2021-38173 btrbk: remote execution in ssh_filter_btrbk.sh [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1994989 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-a66734e7a2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.