Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1230092 Cross-References: * CVE-2024-45310 . # Security update for runc Announcement ID: SUSE-SU-2024:3222-1 Rating: low References: * bsc#1230092 Cross-References: * CVE-2024-45310 CVSS scores: * CVE-2024-45310 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N Affected Products: * Containers Module 15-SP5 * Containers Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * openSUSE Leap Micro 5.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server forSAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for runc fixes the following issues: * Update to runc v1.1.14 * CVE-2024-45310: Fixed an issue where runc can be tricked into creating empty files/directories on host. (bsc#1230092) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.5 zypper in -t patch openSUSE-Leap-Micro-5.5-2024-3222=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3222=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3222=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-3222=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-3222=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-3222=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-3222=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-3222=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2024-3222=1 * Containers Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2024-3222=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-3222=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-3222=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-3222=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-3222=1 * SUSE Linux Enterprise Server15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-3222=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-3222=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-3222=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-3222=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-3222=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-3222=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-3222=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-3222=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-3222=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-3222=1 ## Package List: * openSUSE Leap Micro 5.5 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 *runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * Containers Module 15-SP5 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * Containers Module 15-SP6 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) *runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-150000.70.1 * runc-1.1.14-150000.70.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45310.html * https://bugzilla.suse.com/show_bug.cgi?id=1230092 . SUSE has issued an advisory about a low-severity vulnerability in the runc container runtime, detailing impacts and update instructions for affected products. Container Security Updates, SUSE Advisory, Runc Security Patch. . Severity: Low. LinuxSecurity.com Team
An update that fixes 14 vulnerabilities is now available. . openSUSE Security Update: Security update for opera ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0128-1 Rating: important References: Cross-References: CVE-2024-3832 CVE-2024-3833 CVE-2024-3834 CVE-2024-3837 CVE-2024-3838 CVE-2024-3839 CVE-2024-3840 CVE-2024-3841 CVE-2024-3843 CVE-2024-3844 CVE-2024-3845 CVE-2024-3846 CVE-2024-3847 CVE-2024-3914 CVSS scores: CVE-2024-3834 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2024-3837 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2024-3838 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVE-2024-3839 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.5:NonFree ______________________________________________________________________________ An update that fixes 14 vulnerabilities is now available. Description: This update for opera fixes the following issues: - Update to 110.0.5130.23 * CHR-9706 Update Chromium on desktop-stable-124-5130 to 124.0.6367.62 * DNA-116450 Promote 110 to stable - Complete Opera 110 changelog at: https://blogs.opera.com/desktop/changelog-for-110/ - The update to chromium 124.0.6367.62 fixes following issues: CVE-2024-3832, CVE-2024-3833, CVE-2024-3914, CVE-2024-3834, CVE-2024-3837, CVE-2024-3838, CVE-2024-3839, CVE-2024-3840, CVE-2024-3841, CVE-2024-3843, CVE-2024-3844, CVE-2024-3845, CVE-2024-3846, CVE-2024-3847 - Update to 109.0.5097.80 * DNA-115738 Crash at extensions::ExtensionRegistry:: GetExtensionById(std::__Cr::basic_string const&, int) * DNA-115797 [Flow] Never ending loading while connecting to flow * DNA-116315 Chat GPT in Sidebar Paneldoesnât work - Update to 109.0.5097.59 * CHR-9416 Updating Chromium on desktop-stable-* branches * DNA-115810 Enable #drag-multiple-tabs on all streams - Update to 109.0.5097.45 * CHR-9416 Updating Chromium on desktop-stable-* branches * DNA-114737 [Search box] It's getting blurred when click on it, also lower corners are not rounded sometimes * DNA-115042 '+' button is not responsive when 30+ tabs opened * DNA-115326 Wrong fonts and padding after intake * DNA-115392 [Badges] Text displayed in red * DNA-115501 'Review your payment' native popup has wrong colors * DNA-115809 Enable #show-duplicate-indicator-on-link on all streams Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.5:NonFree: zypper in -t patch openSUSE-2024-128=1 Package List: - openSUSE Leap 15.5:NonFree (x86_64): opera-110.0.5130.23-lp155.3.45.1 References: https://www.suse.com/security/cve/CVE-2024-3832.html https://www.suse.com/security/cve/CVE-2024-3833.html https://www.suse.com/security/cve/CVE-2024-3834.html https://www.suse.com/security/cve/CVE-2024-3837.html https://www.suse.com/security/cve/CVE-2024-3838.html https://www.suse.com/security/cve/CVE-2024-3839.html https://www.suse.com/security/cve/CVE-2024-3840.html https://www.suse.com/security/cve/CVE-2024-3841.html https://www.suse.com/security/cve/CVE-2024-3843.html https://www.suse.com/security/cve/CVE-2024-3844.html https://www.suse.com/security/cve/CVE-2024-3845.html https://www.suse.com/security/cve/CVE-2024-3846.html https://www.suse.com/security/cve/CVE-2024-3847.html https://www.suse.com/security/cve/CVE-2024-3914.html . This critical openSUSE security notification outlines remedies for several opera vulnerabilities. Urgent update suggestedimmediately.. openSUSE Advisory, Opera Update, Security Fix, Patch Management. . Severity: Important. LinuxSecurity.com Team
* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053 . # Security update for slurm_20_02 Announcement ID: SUSE-SU-2024:0310-1 Rating: important References: * bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053 Cross-References: * CVE-2023-49933 * CVE-2023-49936 * CVE-2023-49937 * CVE-2023-49938 CVSS scores: * CVE-2023-49933 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49936 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49936 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-49937 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49937 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-49938 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-49938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * HPC Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for slurm_20_02 fixes the following issues: Security fixes: * CVE-2023-49933: Prevent message extension attacks that could bypass the message hash. (bsc#1218046) * CVE-2023-49936: Prevent NULL pointer dereference on`size_valp` overflow. (bsc#1218050) * CVE-2023-49937: Prevent double-xfree() on error in `_unpack_node_reg_resp()`. (bsc#1218051) * CVE-2023-49938: Prevent modified `sbcast` RPCs from opening a file with the wrong group permissions. (bsc#1218053) Other fixes: * Fix slurm upgrading to incompatible versions (bsc#1216869). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 12 zypper in -t patch SUSE-SLE-Module-HPC-12-2024-310=1 ## Package List: * HPC Module 12 (aarch64 x86_64) * slurm_20_02-plugins-20.02.7-3.20.1 * slurm_20_02-sql-20.02.7-3.20.1 * slurm_20_02-auth-none-debuginfo-20.02.7-3.20.1 * slurm_20_02-lua-debuginfo-20.02.7-3.20.1 * slurm_20_02-20.02.7-3.20.1 * slurm_20_02-debuginfo-20.02.7-3.20.1 * slurm_20_02-sview-debuginfo-20.02.7-3.20.1 * slurm_20_02-lua-20.02.7-3.20.1 * slurm_20_02-slurmdbd-debuginfo-20.02.7-3.20.1 * libnss_slurm2_20_02-debuginfo-20.02.7-3.20.1 * slurm_20_02-pam_slurm-20.02.7-3.20.1 * libslurm35-debuginfo-20.02.7-3.20.1 * slurm_20_02-node-debuginfo-20.02.7-3.20.1 * slurm_20_02-auth-none-20.02.7-3.20.1 * slurm_20_02-plugins-debuginfo-20.02.7-3.20.1 * slurm_20_02-config-20.02.7-3.20.1 * slurm_20_02-devel-20.02.7-3.20.1 * slurm_20_02-torque-20.02.7-3.20.1 * libslurm35-20.02.7-3.20.1 * slurm_20_02-munge-20.02.7-3.20.1 * slurm_20_02-slurmdbd-20.02.7-3.20.1 * slurm_20_02-sql-debuginfo-20.02.7-3.20.1 * slurm_20_02-node-20.02.7-3.20.1 * perl-slurm_20_02-20.02.7-3.20.1 * libpmi0_20_02-debuginfo-20.02.7-3.20.1 * slurm_20_02-torque-debuginfo-20.02.7-3.20.1 * slurm_20_02-doc-20.02.7-3.20.1 * perl-slurm_20_02-debuginfo-20.02.7-3.20.1 * slurm_20_02-debugsource-20.02.7-3.20.1 * slurm_20_02-config-man-20.02.7-3.20.1 * libpmi0_20_02-20.02.7-3.20.1 *slurm_20_02-munge-debuginfo-20.02.7-3.20.1 * slurm_20_02-sview-20.02.7-3.20.1 * libnss_slurm2_20_02-20.02.7-3.20.1 * slurm_20_02-pam_slurm-debuginfo-20.02.7-3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2023-49933.html * https://www.suse.com/security/cve/CVE-2023-49936.html * https://www.suse.com/security/cve/CVE-2023-49937.html * https://www.suse.com/security/cve/CVE-2023-49938.html * https://bugzilla.suse.com/show_bug.cgi?id=1216869 * https://bugzilla.suse.com/show_bug.cgi?id=1218046 * https://bugzilla.suse.com/show_bug.cgi?id=1218050 * https://bugzilla.suse.com/show_bug.cgi?id=1218051 * https://bugzilla.suse.com/show_bug.cgi?id=1218053 . The recent SUSE security advisory regarding slurm_20_02 outlines several critical issues and significant updates pertaining to at-risk components.. SUSE Security Update, Slurm Package Fixes, System Vulnerability Patches, Important Linux Updates. . Severity: Important. LinuxSecurity.com Team
Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3631-1
Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to . MGASA-2023-0300 - Updated libcue packages fix a security vulnerability Publication date: 23 Oct 2023 URL: https://advisories.mageia.org/MGASA-2023-0300.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-43641 Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. (CVE-2023-43641) References: - https://bugs.mageia.org/show_bug.cgi?id=32372 - https://www.openwall.com/lists/oss-security/2023/10/09/3 - https://www.cve.org/CVERecord?id=CVE-2023-43641 SRPMS: - 9/core/libcue-2.3.0-1.mga9 - 8/core/libcue-2.3.0-1.mga8 . Mageia 2023-0301 tackles vulnerabilities in libcue, providing enhancements for KDE users to mitigate potential exploit attempts.. Mageia Security Update, Libcue Exploit Fix, Out-of-Bounds Risk. . Severity: Important. LinuxSecurity.com Team
The container bci/nodejs was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2278-1 Container Tags : bci/node:18 , bci/node:18-8.1 , bci/nodejs:18 , bci/nodejs:18-8.1 Container Release : 8.1 Severity : moderate Type : security References : 1210714 1211430 CVE-2023-1255 CVE-2023-2650 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2620-1 Released: Fri Jun 23 13:41:36 2023 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1210714,1211430,CVE-2023-1255,CVE-2023-2650 This update for openssl-3 fixes the following issues: - CVE-2023-1255: Fixed input buffer over-read in AES-XTS implementation on 64 bit ARM (bsc#1210714). - CVE-2023-2650: Fixed possible DoS translating ASN.1 object identifiers (bsc#1211430). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2811-1 Released: Wed Jul 12 11:56:18 2023 Summary: Recommended update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt Type: recommended Severity: moderate References: This update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt fixes the following issues: This update provides a feature update to the FIDO2 stack. Changes in libfido2: - Version 1.13.0 (2023-02-20) * New API calls: + fido_assert_empty_allow_list; + fido_cred_empty_exclude_list. * fido2-token: fix issue when listing large blobs. - Version 1.12.0 (2022-09-22) * Support for COSE_ES384. * Improved support for FIDO 2.1 authenticators. * New API calls: + es384_pk_free; + es384_pk_from_EC_KEY; +es384_pk_from_EVP_PKEY; + es384_pk_from_ptr; + es384_pk_new; + es384_pk_to_EVP_PKEY; + fido_cbor_info_certs_len; + fido_cbor_info_certs_name_ptr; + fido_cbor_info_certs_value_ptr; + fido_cbor_info_maxrpid_minpinlen; + fido_cbor_info_minpinlen; + fido_cbor_info_new_pin_required; + fido_cbor_info_rk_remaining; + fido_cbor_info_uv_attempts; + fido_cbor_info_uv_modality. * Documentation and reliability fixes. - Version 1.11.0 (2022-05-03) * Experimental PCSC support; enable with -DUSE_PCSC. * Improved OpenSSL 3.0 compatibility. * Use RFC1951 raw deflate to compress CTAP 2.1 largeBlobs. * winhello: advertise 'uv' instead of 'clientPin'. * winhello: support hmac-secret in fido_dev_get_assert(). * New API calls: + fido_cbor_info_maxlargeblob. * Documentation and reliability fixes. * Separate build and regress targets. - Version 1.10.0 (2022-01-17) * bio: fix CTAP2 canonical CBOR encoding in fido_bio_dev_enroll_*(); gh#480. * New API calls: - fido_dev_info_set; - fido_dev_io_handle; - fido_dev_new_with_info; - fido_dev_open_with_info. * Cygwin and NetBSD build fixes. * Documentation and reliability fixes. * Support for TPM 2.0 attestation of COSE_ES256 credentials. - Version 1.9.0 (2021-10-27) * Enabled NFC support on Linux. * Support for FIDO 2.1 'minPinLength' extension. * Support for COSE_EDDSA, COSE_ES256, and COSE_RS1 attestation. * Support for TPM 2.0 attestation. * Support for device timeouts; see fido_dev_set_timeout(). * New API calls: - es256_pk_from_EVP_PKEY; - fido_cred_attstmt_len; - fido_cred_attstmt_ptr; - fido_cred_pin_minlen; - fido_cred_set_attstmt; - fido_cred_set_pin_minlen; - fido_dev_set_pin_minlen_rpid; - fido_dev_set_timeout; - rs256_pk_from_EVP_PKEY. * Reliability and portability fixes. * Better handling of HID devices without identification strings; gh#381. - Update to version 1.8.0: * Better supportfor FIDO 2.1 authenticators. * Support for attestation format 'none'. * New API calls: - fido_assert_set_clientdata; - fido_cbor_info_algorithm_cose; - fido_cbor_info_algorithm_count; - fido_cbor_info_algorithm_type; - fido_cbor_info_transports_len; - fido_cbor_info_transports_ptr; - fido_cred_set_clientdata; - fido_cred_set_id; - fido_credman_set_dev_rk; - fido_dev_is_winhello. * fido2-token: new -Sc option to update a resident credential. * Documentation and reliability fixes. * HID access serialisation on Linux. - Update to version 1.7.0: * hid_win: detect devices with vendor or product IDs > 0x7fff * Support for FIDO 2.1 authenticator configuration. * Support for FIDO 2.1 UV token permissions. * Support for FIDO 2.1 'credBlobs' and 'largeBlobs' extensions. * New API calls * New fido_init flag to disable fido_dev_openâs U2F fallback * Experimental NFC support on Linux. - Enabled hidapi again, issues related to hidapi are fixed upstream - Update to version 1.6.0: * Documentation and reliability fixes. * New API calls: + fido_cred_authdata_raw_len; + fido_cred_authdata_raw_ptr; + fido_cred_sigcount; + fido_dev_get_uv_retry_count; + fido_dev_supports_credman. * Hardened Windows build. * Native FreeBSD and NetBSD support. * Use CTAP2 canonical CBOR when combining hmac-secret and credProtect. - Create a udev subpackage and ship the udev rule. Changes in python-fido2: - update to 0.9.3: * Don't fail device discovery when hidraw doesn't support HIDIOCGRAWUNIQ * Support the latest Windows webauthn.h API (included in Windows 11). * Add product name and serial number to HidDescriptors. * Remove the need for the uhid-freebsd dependency on FreeBSD. - Update to version 0.9.1 * Add new CTAP error codes and improve handling of unknown codes. * Client: API changes to better support extensions. * Client.make_credential now returns a AuthenticatorAttestationResponse, which holds the AttestationObject and ClientData, aswell as any client extension results for the credential. * Client.get_assertion now returns an AssertionSelection object, which is used to select between multiple assertions * Renames: The CTAP1 and CTAP2 classes have been renamed to Ctap1 and Ctap2, respectively. * ClientPin: The ClientPin API has been restructured to support multiple PIN protocols, UV tokens, and token permissions. * CTAP 2.1 PRE: Several new features have been added for CTAP 2.1 * HID: The platform specific HID code has been revamped - Version 0.8.1 (released 2019-11-25) * Bugfix: WindowsClient.make_credential error when resident key requirement is unspecified. - Version 0.8.0 (released 2019-11-25) * New fido2.webauthn classes modeled after the W3C WebAuthn spec introduced. * CTAP2 send_cbor/make_credential/get_assertion and U2fClient request/authenticate timeout arguments replaced with event used to cancel a request. * Fido2Client: - make_credential/get_assertion now take WebAuthn options objects. - timeout is now provided in ms in WebAuthn options objects. Event based cancelation also available by passing an Event. * Fido2Server: - ATTESTATION, USER_VERIFICATION, and AUTHENTICATOR_ATTACHMENT enums have been replaced with fido2.webauthn classes. - RelyingParty has been replaced with PublicKeyCredentialRpEntity, and name is no longer optional. - Options returned by register_begin/authenticate_begin now omit unspecified values if they are optional, instead of filling in default values. - Fido2Server.allowed_algorithms now contains a list of PublicKeyCredentialParameters instead of algorithm identifiers. - Fido2Server.timeout is now in ms and of type int. * Support native WebAuthn API on Windows through WindowsClient. - Version 0.7.2 (released 2019-10-24) * Support for the TPM attestation format. * Allow passing custom challenges to register/authenticate in Fido2Server. * Bugfix: CTAP2 CANCEL command response handling fixed. * Bugfix: Fido2Client fix handling ofempty allow_list. * Bugfix: Fix typo in CTAP2.get_assertions() causing it to fail. - Version 0.7.1 (released 2019-09-20) * Enforce canonical CBOR on Authenticator responses by default. * PCSC: Support extended APDUs. * Server: Verify that UP flag is set. * U2FFido2Server: Implement AppID exclusion extension. * U2FFido2Server: Allow custom U2F facet verification. * Bugfix: U2FFido2Server.authenticate_complete now returns the result. - Version 0.7.0 (released 2019-06-17) * Add support for NFC devices using PCSC. * Add support for the hmac-secret Authenticator extension. * Honor max credential ID length and number of credentials to Authenticator. * Add close() method to CTAP devices to explicitly release their resources. - Version 0.6.0 (released 2019-05-10) * Don't fail if CTAP2 Info contains unknown fields. * Replace cbor loads/dumps functions with encode/decode/decode_from. * Server: Add support for AuthenticatorAttachment. * Server: Add support for more key algorithms. * Client: Expose CTAP2 Info object as Fido2Client.info. Changes in yubikey-manager: - Update to version 4.0.9 (released 2022-06-17) * Dependency: Add support for python-fido2 1.x * Fix: Drop stated support for Click 6 as features from 7 are being used. - Update to version 4.0.8 (released 2022-01-31) * Bugfix: Fix error message for invalid modhex when programing a YubiOTP credential. * Bugfix: Fix issue with displaying a Steam credential when it is the only account. * Bugfix: Prevent installation of files in site-packages root. * Bugfix: Fix cleanup logic in PIV for protected management key. * Add support for token identifier when programming slot-based HOTP. * Add support for programming NDEF in text mode. * Dependency: Add support for Cryptography â 38. - version update to 4.0.7 ** Bugfix release: Fix broken naming for 'YubiKey 4', and a small OATH issue with touch Steam credentials. - version 4.0.6 (released 2021-09-08) ** Improve handling of YubiKey devicereboots. ** More consistently mask PIN/password input in prompts. ** Support switching mode over CCID for YubiKey Edge. ** Run pkill from PATH instead of fixed location. - version 4.0.5 (released 2021-07-16) ** Bugfix: Fix PIV feature detection for some YubiKey NEO versions. ** Bugfix: Fix argument short form for --period when adding TOTP credentials. ** Bugfix: More strict validation for some arguments, resulting in better error messages. ** Bugfix: Correctly handle TOTP credentials using period != 30 AND touch_required. ** Bugfix: Fix prompting for access code in the otp settings command (now uses '-A -'). - Update to version 4.0.3 * Add support for fido reset over NFC. * Bugfix: The --touch argument to piv change-management-key was ignored. * Bugfix: Donât prompt for password when importing PIV key/cert if file is invalid. * Bugfix: Fix setting touch-eject/auto-eject for YubiKey 4 and NEO. * Bugfix: Detect PKCS#12 format when outer sequence uses indefinite length. * Dependency: Add support for Click 8. - Update to version 4.0.2 * Update device names * Add read_info output to the --diagnose command, and show exception types. * Bugfix: Fix read_info for YubiKey Plus. * Add support for YK5-based FIPS YubiKeys. * Bugfix: Fix OTP device enumeration on Win32. * Drop reliance on libusb and libykpersonalize. * Support the 'fido' and 'otp' subcommands over NFC * New 'ykman --diagnose' command to aid in troubleshooting. * New 'ykman apdu' command for sending raw APDUs over the smart card interface. * New 'yubikit' package added for custom development and advanced scripting. * OpenPGP: Add support for KDF enabled YubiKeys. * Static password: Add support for FR, IT, UK and BEPO keyboard layouts. - Update to 3.1.1 * Add support for YubiKey 5C NFC * OpenPGP: set-touch now performs compatibility checks before prompting for PIN * OpenPGP: Improve error messages and documentation for set-touch * PIV: read-objectcommand no longer adds a trailing newline * CLI: Hint at missing permissions when opening a device fails * Linux: Improve error handling when pcscd is not running * Windows: Improve how .DLL files are loaded, thanks to Marius Gabriel Mihai for reporting this! * Bugfix: set-touch now accepts the cached-fixed option * Bugfix: Fix crash in OtpController.prepare_upload_key() error parsing * Bugfix: Fix crash in piv info command when a certificate slot contains an invalid certificate * Library: PivController.read_certificate(slot) now wraps certificate parsing exceptions in new exception type InvalidCertificate * Library: PivController.list_certificates() now returns None for slots containing invalid certificate, instead of raising an exception - Version 3.1.0 (released 2019-08-20) * Add support for YubiKey 5Ci * OpenPGP: the info command now prints OpenPGP specification version as well * OpenPGP: Update support for attestation to match OpenPGP v3.4 * PIV: Use UTC time for self-signed certificates * OTP: Static password now supports the Norman keyboard layout - Version 3.0.0 (released 2019-06-24) * Add support for new YubiKey Preview and lightning form factor * FIDO: Support for credential management * OpenPGP: Support for OpenPGP attestation, cardholder certificates and cached touch policies * OTP: Add flag for using numeric keypad when sending digits - Version 2.1.1 (released 2019-05-28) * OTP: Add initial support for uploading Yubico OTP credentials to YubiCloud * Donât automatically select the U2F applet on YubiKey NEO, it might be blocked by the OS * ChalResp: Always pad challenge correctly * Bugfix: Donât crash with older versions of cryptography * Bugfix: Password was always prompted in OATH command, even if sent as argument Changes in yubikey-manager-qt: - update to 1.2.5: * Compatibility update for ykman 5.0.1. * Update to Python 3.11. * Update product images. - Update to version 1.2.4 (released 2021-10-26) * Update devicenames and images. * PIV: Fix import of certificate. - Update to version 1.2.3 * Improved error handling when using Security Key Series devices. * PIV: Fix generation of certificate in slot 9c. - Update to version 1.2.2 * Fix detection of YubiKey Plus * Compatibility update for yubikey-manager 4.0 * Bugfix: Device caching with multiple devices * Drop dependencies on libusb and libykpers. * Add additional product names and images - update to 1.1.5 * Add support for YubiKey 5C NFC - Update to version 1.1.4 * OTP: Add option to upload YubiOTP credential to YubiCloud * Linux: Show hint about pcscd service if opening device fails * Bugfix: Signal handling now compatible with Python 3.8 - Version 1.1.3 (released 2019-08-20) * Add suppport for YubiKey 5Ci * PIV: Use UTC time for self-signed certificates - Version 1.1.2 (released 2019-06-24) * Add support for new YubiKey Preview * PIV: The popup for the management key now have a 'Use default' option * Windows: Fix issue with importing PIV certificates * Bugfix: generate static password now works correctly The following package changes have been done: - crypto-policies-20210917.c9d86d1-150400.1.7 added - libhidapi-hidraw0-0.10.1-1.6 added - libopenssl3-3.0.8-150500.5.3.1 added - libfido2-1-1.13.0-150400.5.3.1 updated - libfido2-udev-1.5.0-1.30 removed . The most recent security upgrade for the bci/nodejs container features critical fixes and guidance for users to ensure their environments remain secure.. SUSE Container Update,bci/nodejs advisory,security updates for containers,open source security patches. . LinuxSecurity.com Team
An update for python-flask is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: python-flask security update Advisory ID: RHSA-2023:3525-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2023:3525 Issue date: 2023-06-07 CVE Names: CVE-2023-30861 ==================================================================== 1. Summary: An update for python-flask is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux 7 Extras - noarch 3. Description: Flask is a lightweight but extensible web development framework for Python based on the Werkzeug WSGI toolkit, and the Jinja 2 template engine. Security Fix(es): * flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie header (CVE-2023-30861) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2196643 - CVE-2023-30861 flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie header 6. Package List: Red Hat Enterprise Linux 7Extras: Source: python-flask-0.10.1-7.el7_9.src.rpm noarch: python-flask-0.10.1-7.el7_9.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-30861 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZIBw+tzjgjWX9erEAQjDww//S0Ay3p4qP1Fgqkw8/bD8nMc9QtBH6bRo McQKI/qOpSg7l4qqX4/Dlvos2r1CElc0LboTyzJ0J3shx+klVfUmXLrfYgSs7Jw3 /ooZxJjutrdkvgez3norOuHQFqb418AUqmLSH2fDYtFNXlZyqSs08eo3xOsQf7N+ FdPii6tMuiSUHdAj4yhBzp60ThBCm6CNyVFQfjZSKTNDDwuoB3zZIdWpIDz2lxtd yAjLCMKGw4kHLmGO+c4OXEhHK4vbUqk6+3xuJ4elzc90seEodI61c88To6DUe4L3 BrZlfr3hugFefyl4wzRUYvSA9iJLmzdwbHUYpAQHZ90C2X63it66sEw3pdrflV80 yj/0Gz8iVL/SHXAyeSj5AEIBmsegCCwZZvZnFufUQptZBioAAQbNCSPYH2WXLVLL XBfSlLTPYd6Xo6bIQ3xFAdqEEKiaQ+vykOaUkYYEcXdE06CYcApLm+B6nZdJrSTd WvCy1G82DMEXNtAwrhULCcVHJOfx8v9xWKiKT71ipYvzj1MR2vvdnIuxbEfYHoiv TbVgX08ixx+vyd+w0rHJmWIe96Gyzy1LzGa0xEzyNVJLv1yz50TAVaJq3A8bkKuD zk93nnlEA9WGuc11313bG2QwLRu/wJUeoRy7TzyMIkTB9Es+Um6PgdbEGna0hHZ5 tmpg/ZT8uAU=P970 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A memory corruption issue that could be triggered when diffing binary files. (CVE-2014-9862) References: - https://bugs.mageia.org/show_bug.cgi?id=30819 . MGASA-2022-0334 - Updated ostree packages fix security vulnerability Publication date: 16 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0334.html Type: security Affected Mageia releases: 8 CVE: CVE-2014-9862 A memory corruption issue that could be triggered when diffing binary files. (CVE-2014-9862) References: - https://bugs.mageia.org/show_bug.cgi?id=30819 - https://lists.suse.com/pipermail/sle-security-updates/2022-September/012105.html - - https://www.cve.org/CVERecord?id=CVE-2014-9862 SRPMS: - 8/core/ostree-2020.8-2.1.mga8 . Memory integrity flaw fixed in Mageia 8 with new ostree updates, mitigating potential security threat.. Mageia Security Update, Memory Issue, Ostree Package Update, Software Vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.