Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Backport fix for CVE-2024-4032.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-1ecab28e50 2024-07-12 04:17:37.731120 -------------------------------------------------------------------------------- Name : mingw-python3 Product : Fedora 40 Version : 3.11.8 Release : 2.fc40 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2024-4032. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 3 2024 Sandro Mani - 3.11.8-2 - Backport patch for CVE-2024-4032 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2293389 - CVE-2024-4032 mingw-python3: python: incorrect IPv4 and IPv6 private ranges [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2293389 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-1ecab28e50' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1214691 * bsc#1219666 Cross-References: * CVE-2022-48566 . # Security update for python3 Announcement ID: SUSE-SU-2024:0901-1 Rating: important References: * bsc#1214691 * bsc#1219666 Cross-References: * CVE-2022-48566 * CVE-2023-6597 CVSS scores: * CVE-2022-48566 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2022-48566 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-6597 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP5 * Development Tools Module 15-SP5 * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2023-6597: Fixed symlink bug in cleanup of tempfile.TemporaryDirectory (bsc#1219666). * CVE-2022-48566: Make compare_digest more constant-time (bsc#1214691). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-901=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-901=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-901=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-901=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-901=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-901=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-901=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-901=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-901=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-901=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-901=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-901=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-901=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-901=1 * SUSELinux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-901=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-901=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-901=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-901=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-901=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-901=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-901=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-901=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-901=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-901=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-901=1 ## Package List: * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python3-testsuite-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-testsuite-3.6.15-150300.10.57.1 * python3-doc-devhelp-3.6.15-150300.10.57.1 * python3-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 *python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * python3-doc-3.6.15-150300.10.57.1 * openSUSE Leap 15.5 (x86_64) * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-32bit-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 *libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 *python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Manager Proxy 4.3 (x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python3-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 *python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python3-testsuite-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-testsuite-3.6.15-150300.10.57.1 * python3-doc-devhelp-3.6.15-150300.10.57.1 * python3-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-curses-debuginfo-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * python3-devel-debuginfo-3.6.15-150300.10.57.1 * python3-dbm-3.6.15-150300.10.57.1 * python3-tk-3.6.15-150300.10.57.1 * python3-dbm-debuginfo-3.6.15-150300.10.57.1 * python3-curses-3.6.15-150300.10.57.1 * python3-tools-3.6.15-150300.10.57.1 *python3-debugsource-3.6.15-150300.10.57.1 * python3-idle-3.6.15-150300.10.57.1 * python3-devel-3.6.15-150300.10.57.1 * python3-tk-debuginfo-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 * python3-doc-3.6.15-150300.10.57.1 * openSUSE Leap 15.3 (x86_64) * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-32bit-3.6.15-150300.10.57.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libpython3_6m1_0-64bit-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-64bit-3.6.15-150300.10.57.1 * openSUSE Leap Micro 5.3 (aarch64 x86_64) * python3-3.6.15-150300.10.57.1 * python3-debugsource-3.6.15-150300.10.57.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.57.1 * python3-base-3.6.15-150300.10.57.1 * python3-core-debugsource-3.6.15-150300.10.57.1 * python3-debuginfo-3.6.15-150300.10.57.1 * libpython3_6m1_0-3.6.15-150300.10.57.1 * python3-base-debuginfo-3.6.15-150300.10.57.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48566.html * https://www.suse.com/security/cve/CVE-2023-6597.html * https://bugzilla.suse.com/show_bug.cgi?id=1214691 * https://bugzilla.suse.com/show_bug.cgi?id=1219666 . Significant python3 enhancement resolves multiple concerns, tackling symlink vulnerabilities and boosting security through consistent-time evaluations.. SUSE Linux Update, Python3 Security Patch, SUSE Notification, Python Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4334-1 Container Tags : bci/python:3 , bci/python:3-12.58 , bci/python:3.11 , bci/python:3.11-12.58 , bci/python:latest Container Release : 12.58 Severity : important Type : security References : 1216987 1217353 CVE-2023-5752 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4962-1 Released: Fri Dec 22 13:45:06 2023 Summary: Recommended update for curl Type: recommended Severity: important References: 1216987 This update for curl fixes the following issues: - libssh: Implement SFTP packet size limit (bsc#1216987) This update also ships curl to the INSTALLER channel. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4988-1 Released: Thu Dec 28 16:06:49 2023 Summary: Security update for python-pip Type: security Severity: low References: 1217353,CVE-2023-5752 This update for python-pip fixes the following issues: - CVE-2023-5752: Fixed injection of arbitrary configuration through Mercurial parameter (bsc#1217353). The following package changes have been done: - libcurl4-8.0.1-150400.5.41.1 updated - curl-8.0.1-150400.5.41.1 updated - python311-pip-22.3.1-150400.17.12.1 updated - container:sles15-image-15.0.0-36.5.68 updated . SUSE Container Update Notice details important updates for bci/python, enhancing security and fixing issues with notable patches.. SUSE Update Advisory,bci/python Security Update,container security patches. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3811 https://linux.oracle.com/errata/ELSA-2023-3811.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: python39-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.x86_64.rpm python39-cffi-1.14.3-2.module+el8.4.0+20109+b7b1db01.x86_64.rpm python39-chardet-3.0.4-19.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-cryptography-3.3.1-2.module+el8.4.0+20109+b7b1db01.x86_64.rpm python39-debug-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.x86_64.rpm python39-devel-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.x86_64.rpm python39-idle-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.x86_64.rpm python39-idna-2.10-3.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-libs-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.x86_64.rpm python39-lxml-4.6.5-1.module+el8.6.0+20625+ee813db2.x86_64.rpm python39-mod_wsgi-4.7.1-5.module+el8.7.0+20870+babacad2.x86_64.rpm python39-numpy-1.19.4-3.module+el8.5.0+20364+c7fe1181.x86_64.rpm python39-numpy-doc-1.19.4-3.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-numpy-f2py-1.19.4-3.module+el8.5.0+20364+c7fe1181.x86_64.rpm python39-pip-20.2.4-7.module+el8.6.0+20625+ee813db2.noarch.rpm python39-pip-wheel-20.2.4-7.module+el8.6.0+20625+ee813db2.noarch.rpm python39-ply-3.11-10.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-psutil-5.8.0-4.module+el8.4.0+20109+b7b1db01.x86_64.rpm python39-psycopg2-2.8.6-2.module+el8.4.0+20109+b7b1db01.x86_64.rpm python39-psycopg2-doc-2.8.6-2.module+el8.4.0+20109+b7b1db01.x86_64.rpm python39-psycopg2-tests-2.8.6-2.module+el8.4.0+20109+b7b1db01.x86_64.rpm python39-pycparser-2.20-3.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-PyMySQL-0.10.1-2.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-pysocks-1.7.1-4.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-pyyaml-5.4.1-1.module+el8.5.0+20364+c7fe1181.x86_64.rpm python39-requests-2.25.0-2.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-rpm-macros-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.noarch.rpm python39-scipy-1.5.4-3.module+el8.4.0+20109+b7b1db01.x86_64.rpm python39-setuptools-50.3.2-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-setuptools-wheel-50.3.2-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-six-1.15.0-3.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-test-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.x86_64.rpm python39-tkinter-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.x86_64.rpm python39-toml-0.10.1-5.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-urllib3-1.25.10-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-wheel-0.35.1-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-wheel-wheel-0.35.1-4.module+el8.5.0+20364+c7fe1181.noarch.rpm aarch64: python39-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.aarch64.rpm python39-cffi-1.14.3-2.module+el8.4.0+20109+b7b1db01.aarch64.rpm python39-chardet-3.0.4-19.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-cryptography-3.3.1-2.module+el8.4.0+20109+b7b1db01.aarch64.rpm python39-debug-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.aarch64.rpm python39-devel-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.aarch64.rpm python39-idle-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.aarch64.rpm python39-idna-2.10-3.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-libs-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.aarch64.rpm python39-lxml-4.6.5-1.module+el8.6.0+20625+ee813db2.aarch64.rpm python39-mod_wsgi-4.7.1-5.module+el8.7.0+20870+babacad2.aarch64.rpm python39-numpy-1.19.4-3.module+el8.5.0+20364+c7fe1181.aarch64.rpm python39-numpy-doc-1.19.4-3.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-numpy-f2py-1.19.4-3.module+el8.5.0+20364+c7fe1181.aarch64.rpm python39-pip-20.2.4-7.module+el8.6.0+20625+ee813db2.noarch.rpm python39-pip-wheel-20.2.4-7.module+el8.6.0+20625+ee813db2.noarch.rpm python39-ply-3.11-10.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-psutil-5.8.0-4.module+el8.4.0+20109+b7b1db01.aarch64.rpm python39-psycopg2-2.8.6-2.module+el8.4.0+20109+b7b1db01.aarch64.rpm python39-psycopg2-doc-2.8.6-2.module+el8.4.0+20109+b7b1db01.aarch64.rpm python39-psycopg2-tests-2.8.6-2.module+el8.4.0+20109+b7b1db01.aarch64.rpm python39-pycparser-2.20-3.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-PyMySQL-0.10.1-2.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-pysocks-1.7.1-4.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-pyyaml-5.4.1-1.module+el8.5.0+20364+c7fe1181.aarch64.rpm python39-requests-2.25.0-2.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-rpm-macros-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.noarch.rpm python39-scipy-1.5.4-3.module+el8.4.0+20109+b7b1db01.aarch64.rpm python39-setuptools-50.3.2-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-setuptools-wheel-50.3.2-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-six-1.15.0-3.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-test-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.aarch64.rpm python39-tkinter-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.aarch64.rpm python39-toml-0.10.1-5.module+el8.4.0+20109+b7b1db01.noarch.rpm python39-urllib3-1.25.10-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-wheel-0.35.1-4.module+el8.5.0+20364+c7fe1181.noarch.rpm python39-wheel-wheel-0.35.1-4.module+el8.5.0+20364+c7fe1181.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//mod_wsgi-4.7.1-5.module+el8.7.0+20870+babacad2.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//numpy-1.19.4-3.module+el8.5.0+20364+c7fe1181.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python39-3.9.16-1.module+el8.8.0+21116+ee8c18cf.1.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python3x-pip-20.2.4-7.module+el8.6.0+20625+ee813db2.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python3x-setuptools-50.3.2-4.module+el8.5.0+20364+c7fe1181.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python3x-six-1.15.0-3.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-cffi-1.14.3-2.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-chardet-3.0.4-19.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-cryptography-3.3.1-2.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-idna-2.10-3.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-lxml-4.6.5-1.module+el8.6.0+20625+ee813db2.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-ply-3.11-10.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-psutil-5.8.0-4.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-psycopg2-2.8.6-2.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-pycparser-2.20-3.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-PyMySQL-0.10.1-2.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-pysocks-1.7.1-4.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-requests-2.25.0-2.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-toml-0.10.1-5.module+el8.4.0+20109+b7b1db01.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-urllib3-1.25.10-4.module+el8.5.0+20364+c7fe1181.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//python-wheel-0.35.1-4.module+el8.5.0+20364+c7fe1181.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//PyYAML-5.4.1-1.module+el8.5.0+20364+c7fe1181.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//scipy-1.5.4-3.module+el8.4.0+20109+b7b1db01.src.rpm Related CVEs: CVE-2023-24329 Description of changes: python39 [3.9.16-1.1] - Security fix for CVE-2023-24329 _______________________________________________ El-errata mailing list
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:169-1 Container Tags : bci/python:3 , bci/python:3-11.4 , bci/python:3.10 , bci/python:3.10-11.4 , bci/python:latest Container Release : 11.4 Severity : moderate Type : security References : 1206667 CVE-2022-40897 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:91-1 Released: Mon Jan 16 11:14:14 2023 Summary: Security update for python310-setuptools Type: security Severity: moderate References: 1206667,CVE-2022-40897 This update for python310-setuptools fixes the following issues: - CVE-2022-40897: Fixed an excessive CPU usage that could be triggered by fetching a malicious HTML document (bsc#1206667). The following package changes have been done: - python310-setuptools-57.4.0-150400.4.3.1 updated . The latest SUSE Container Update for bci/node introduces essential security enhancements and resolves memory optimization concerns within Node.js libraries.. SUSE Container, Python Security, Container Update, Moderate Severity, CPU Usage Fix. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-4930 https://linux.oracle.com/errata/ELSA-2022-4930.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: python-twisted-web-12.1.0-8.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/python-twisted-web-12.1.0-8.el7_9.src.rpm Related CVEs: CVE-2022-24801 Description of changes: [12.1.0-8] - Security fix for CVE-2022-24801: Possible http request smuggling Resolves: rhbz#2073114 _______________________________________________ El-errata mailing list
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:464-1 Container Tags : bci/python:3.6 , bci/python:3.6-12.38 Container Release : 12.38 Severity : important Type : security References : 1195258 1196093 1197024 1197459 CVE-2018-25032 CVE-2021-22570 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1040-1 Released: Wed Mar 30 09:40:58 2022 Summary: Security update for protobuf Type: security Severity: moderate References: 1195258,CVE-2021-22570 This update for protobuf fixes the following issues: - CVE-2021-22570: Fix incorrect parsing of nullchar in the proto symbol (bsc#1195258). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1047-1 Released: Wed Mar 30 16:20:56 2022 Summary: Recommended update for pam Type: recommended Severity: moderate References: 1196093,1197024 This update for pam fixes the following issues: - Define _pam_vendordir as the variable is needed by systemd and others. (bsc#1196093) - Between allocating the variable 'ai' and free'ing them, there are two 'return NO' were we don't free this variable. This patch inserts freaddrinfo() calls before the 'return NO;'s. (bsc#1197024) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1061-1 Released: Wed Mar 30 18:27:06 2022 Summary: Security update for zlib Type: security Severity: important References: 1197459,CVE-2018-25032 This update for zlib fixes the following issues: - CVE-2018-25032: Fixed memory corruption on deflate (bsc#1197459). The following packagechanges have been done: - libprotobuf-lite20-3.9.2-4.12.1 updated - libz1-1.2.11-150000.3.30.1 updated - pam-1.3.0-150000.6.55.3 updated - container:sles15-image-15.0.0-17.11.16 updated . SUSE has released critical security patches for bci/python container, fixing vulnerabilities like buffer overflows and denial-of-service exploits for improved safety. SUSE Container, Python Update, Security Patch, Important Advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes 13 vulnerabilities is now available. . SUSE Security Update: Security update for java-1_7_0-openjdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0049-1 Rating: important References: #1101644 #1101645 #1101651 #1101656 #1112142 #1112143 #1112144 #1112146 #1112147 #1112152 #1112153 Cross-References: CVE-2018-13785 CVE-2018-16435 CVE-2018-2938 CVE-2018-2940 CVE-2018-2952 CVE-2018-2973 CVE-2018-3136 CVE-2018-3139 CVE-2018-3149 CVE-2018-3169 CVE-2018-3180 CVE-2018-3214 CVE-2018-3639 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update for java-1_7_0-openjdk to version 7u201 fixes the following issues: Security issues fixed: - CVE-2018-3136: Manifest better support (bsc#1112142) - CVE-2018-3139: Better HTTP Redirection (bsc#1112143) - CVE-2018-3149: Enhance JNDI lookups (bsc#1112144) - CVE-2018-3169: Improve field accesses (bsc#1112146) - CVE-2018-3180: Improve TLS connections stability (bsc#1112147) - CVE-2018-3214: Better RIFF reading support (bsc#1112152) - CVE-2018-13785: Upgrade JDK 8u to libpng 1.6.35(bsc#1112153) - CVE-2018-16435: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile - CVE-2018-2938: Support Derby connections (bsc#1101644) - CVE-2018-2940: Better stack walking (bsc#1101645) - CVE-2018-2952: Exception to Pattern Syntax (bsc#1101651) - CVE-2018-2973: Improve LDAP support (bsc#1101656) - CVE-2018-3639 cpu speculative store bypass mitigation Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-49=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-49=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-49=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-49=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-49=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-49=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-49=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2019-49=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-49=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-49=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-49=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Enterprise Storage 4 (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 References: https://www.suse.com/security/cve/CVE-2018-13785.html https://www.suse.com/security/cve/CVE-2018-16435.html https://www.suse.com/security/cve/CVE-2018-2938.html https://www.suse.com/security/cve/CVE-2018-2940.html https://www.suse.com/security/cve/CVE-2018-2952.html https://www.suse.com/security/cve/CVE-2018-2973.html https://www.suse.com/security/cve/CVE-2018-3136.html https://www.suse.com/security/cve/CVE-2018-3139.html https://www.suse.com/security/cve/CVE-2018-3149.html https://www.suse.com/security/cve/CVE-2018-3169.html https://www.suse.com/security/cve/CVE-2018-3180.html https://www.suse.com/security/cve/CVE-2018-3214.html https://www.suse.com/security/cve/CVE-2018-3639.html https://bugzilla.suse.com/1101644 https://bugzilla.suse.com/1101645 https://bugzilla.suse.com/1101651 https://bugzilla.suse.com/1101656 https://bugzilla.suse.com/1112142 https://bugzilla.suse.com/1112143 https://bugzilla.suse.com/1112144 https://bugzilla.suse.com/1112146 https://bugzilla.suse.com/1112147 https://bugzilla.suse.com/1112152 https://bugzilla.suse.com/1112153 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.