Explore top 10 tips to secure your open-source projects now. Read More
×Moderate: mariadb:10.3 security, bug fix, and enhancement update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5259", "synopsis": "Moderate: mariadb:10.3 security, bug fix, and enhancement update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.mariadb, galera, Judy, module.galera, mariadb, module.Judy.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. \n\nThe following packages have been upgraded to a later upstream version: mariadb (10.3). (BZ#2223572, BZ#2223574, BZ#2223962, BZ#2223965)\n\nSecurity Fix(es):\n\n* mariadb: segmentation fault via the component sub_select (CVE-2022-32084)\n\n* mariadb: server crash in JOIN_CACHE::free or in copy_fields (CVE-2022-32091)\n\n* mariadb: compress_write() fails to release mutex on failure (CVE-2022-38791)\n\n* mariadb: NULL pointer dereference in spider_db_mbase::print_warnings() (CVE-2022-47015)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* [MariaDB 10.3.32] socat: E Failed to set SNI host \"\" (SST failure) (BZ#2223961)", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2106034", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106034", "description": ""}, {"ticket": "2106042", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106042", "description": ""}, {"ticket": "2130105", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2130105", "description": ""}, {"ticket": "2163609", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2163609","description": ""}, {"ticket": "2240246", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2240246", "description": ""}], "cves": [{"name": "CVE-2022-32084", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32084", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-229"}, {"name": "CVE-2022-32091", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32091", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-229"}, {"name": "CVE-2022-38791", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-38791", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-667"}, {"name": "CVE-2022-47015", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-47015", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-476"}, {"name": "CVE-2023-5157", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5157", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2025-12-27T09:04:03.511459Z", "rpms": {"Rocky Linux 8": {"nvras": ["galera-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "galera-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.src.rpm", "galera-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "galera-debuginfo-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "galera-debuginfo-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "galera-debugsource-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "galera-debugsource-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+431+26aaed18.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm","Judy-0:1.0.5-18.module+el8.10.0+1925+356c22e8.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.src.rpm", "Judy-0:1.0.5-18.module+el8.10.0+1674+fa55eae9.src.rpm", "Judy-0:1.0.5-18.module+el8.10.0+1925+356c22e8.src.rpm", "Judy-0:1.0.5-18.module+el8.4.0+431+26aaed18.src.rpm", "Judy-0:1.0.5-18.module+el8.4.0+431+26aaed18.x86_64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.x86_64.rpm", "Judy-0:1.0.5-18.module+el8.10.0+1925+356c22e8.x86_64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+431+26aaed18.aarch64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.10.0+1925+356c22e8.aarch64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+427+adf35707.x86_64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+431+26aaed18.x86_64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.10.0+1925+356c22e8.x86_64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.10.0+1925+356c22e8.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+431+26aaed18.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+431+26aaed18.x86_64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.10.0+1925+356c22e8.x86_64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+427+adf35707.x86_64.rpm", "mariadb-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.src.rpm", "mariadb-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-backup-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-backup-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-backup-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-backup-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-common-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-common-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm","mariadb-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-debugsource-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-debugsource-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-embedded-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-embedded-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-embedded-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-embedded-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-embedded-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-embedded-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-errmsg-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-errmsg-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-gssapi-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-gssapi-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-gssapi-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-gssapi-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-oqgraph-engine-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-oqgraph-engine-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-oqgraph-engine-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-oqgraph-engine-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-galera-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm","mariadb-server-galera-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-utils-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-utils-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-utils-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-utils-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-test-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-test-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-test-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-test-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Updates available for Rocky Linux mariadb include security fixes for several vulnerabilities; important enhancements addressed.. moderate mariadb update security issues enhancements. . Severity: moderate. LinuxSecurity.com Team
A vulnerability has been discovered in rust-openssl, a set of OpenSSL bindings for the Rust programming language. In affected versions ssl::select_next_proto can return a slice pointing . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4049-1
* bsc#1216171 * bsc#1229155 Cross-References: * CVE-2023-44487 . # Security update for nginx Announcement ID: SUSE-SU-2025:0283-1 Release Date: 2025-01-29T12:33:31Z Rating: important References: * bsc#1216171 * bsc#1229155 Cross-References: * CVE-2023-44487 * CVE-2024-7347 CVSS scores: * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7347 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-7347 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-7347 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for nginx fixes the following issues: * CVE-2023-44487: Mitigate HTTP/2 Rapid Reset Attack (bsc#1216171) * CVE-2024-7347: Fixed worker crashes on special crafted mp4 files containing invalid chunk information (bsc#1229155) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-283=1 openSUSE-SLE-15.6-2025-283=1 * Server Applications Module 15-SP6 zypper in -t patchSUSE-SLE-Module-Server-Applications-15-SP6-2025-283=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * nginx-debugsource-1.21.5-150600.10.3.1 * nginx-debuginfo-1.21.5-150600.10.3.1 * nginx-1.21.5-150600.10.3.1 * openSUSE Leap 15.6 (noarch) * nginx-source-1.21.5-150600.10.3.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.3.1 * nginx-debuginfo-1.21.5-150600.10.3.1 * nginx-1.21.5-150600.10.3.1 * Server Applications Module 15-SP6 (noarch) * nginx-source-1.21.5-150600.10.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-44487.html * https://www.suse.com/security/cve/CVE-2024-7347.html * https://bugzilla.suse.com/show_bug.cgi?id=1216171 * https://bugzilla.suse.com/show_bug.cgi?id=1229155 . Recent security enhancements for nginx highlight essential patches addressing multiple vulnerabilities in SUSE environments. It's important to implement them without delay.. nginx security, SUSE updates, HTTP2 vulnerabilities, software patches. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for nginx Announcement ID: SUSE-SU-2025:0282-1 Release Date: 2025-01-29T08:04:15Z Rating: important References: * bsc#1216171 * bsc#1229155 Cross-References: * CVE-2023-44487 * CVE-2024-7347 CVSS scores: * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7347 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-7347 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-7347 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for nginx fixes the followingissues: * CVE-2023-44487: Mitigate HTTP/2 Rapid Reset Attack (bsc#1216171) * CVE-2024-7347: Fixed worker crashes on special crafted mp4 files containing invalid chunk information (bsc#1229155) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-282=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-282=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-282=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-282=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-282=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-282=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-282=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-282=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-282=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-282=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-282=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-282=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 *nginx-debugsource-1.21.5-150400.3.6.1 * openSUSE Leap 15.4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) *nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Manager Proxy 4.3 (x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Manager Proxy 4.3 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Manager Server 4.3 (noarch) * nginx-source-1.21.5-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-44487.html * https://www.suse.com/security/cve/CVE-2024-7347.html * https://bugzilla.suse.com/show_bug.cgi?id=1216171 * https://bugzilla.suse.com/show_bug.cgi?id=1229155 . Crucial Apache security patch released for Fedora addressing HTTP/3 flaws and server instabilities. Keep your systems safe.. nginx security update, openSUSE patch, HTTP/2 vulnerabilities, Linux server security. . Severity: Important. LinuxSecurity.com Team
* bsc#1215799 * jsc#ECO-3633 Cross-References: * CVE-2023-5215 . # Security update for libnbd Announcement ID: SUSE-SU-2023:4222-1 Rating: moderate References: * bsc#1215799 * jsc#ECO-3633 Cross-References: * CVE-2023-5215 CVSS scores: * CVE-2023-5215 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-5215 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for libnbd fixes the following issues: * Updated to version 1.18.1 * Updated to version 1.18.0: * CVE-2023-5215: Fixed an issue where an NBD server returning an unexpected block size might crash an application (bsc#1215799). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2023-4222=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4222=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4222=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * libnbd-debuginfo-1.18.1-150300.8.15.1 * libnbd0-1.18.1-150300.8.15.1 * libnbd-debugsource-1.18.1-150300.8.15.1 * libnbd-devel-1.18.1-150300.8.15.1 * python3-libnbd-debuginfo-1.18.1-150300.8.15.1 * python3-libnbd-1.18.1-150300.8.15.1 * nbdfuse-1.18.1-150300.8.15.1 * nbdfuse-debuginfo-1.18.1-150300.8.15.1 * libnbd-1.18.1-150300.8.15.1 * libnbd0-debuginfo-1.18.1-150300.8.15.1 * openSUSE Leap 15.3 (noarch) * libnbd-bash-completion-1.18.1-150300.8.15.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libnbd-debuginfo-1.18.1-150300.8.15.1 * libnbd0-1.18.1-150300.8.15.1 *libnbd-debugsource-1.18.1-150300.8.15.1 * libnbd-devel-1.18.1-150300.8.15.1 * nbdfuse-1.18.1-150300.8.15.1 * nbdfuse-debuginfo-1.18.1-150300.8.15.1 * libnbd-1.18.1-150300.8.15.1 * libnbd0-debuginfo-1.18.1-150300.8.15.1 * openSUSE Leap 15.4 (noarch) * libnbd-bash-completion-1.18.1-150300.8.15.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libnbd-debuginfo-1.18.1-150300.8.15.1 * libnbd0-1.18.1-150300.8.15.1 * libnbd-debugsource-1.18.1-150300.8.15.1 * libnbd-devel-1.18.1-150300.8.15.1 * python3-libnbd-debuginfo-1.18.1-150300.8.15.1 * python3-libnbd-1.18.1-150300.8.15.1 * nbdfuse-1.18.1-150300.8.15.1 * nbdfuse-debuginfo-1.18.1-150300.8.15.1 * libnbd-1.18.1-150300.8.15.1 * libnbd0-debuginfo-1.18.1-150300.8.15.1 * openSUSE Leap 15.5 (noarch) * libnbd-bash-completion-1.18.1-150300.8.15.1 ## References: * https://www.suse.com/security/cve/CVE-2023-5215.html * https://bugzilla.suse.com/show_bug.cgi?id=1215799 * https://idp-saml.suse.com/simplesaml/module.php/core/loginuserpass.php?AuthState=_2e768f13e6e4c5ee29e46ac966c3b389ab09d2f55a%3Ahttps%3A%2F%2Fidp-saml.suse.com%2Fsimplesaml%2Fsaml2%2Fidp%2FSSOService.php%3Fspentityid%3Dhttps%253A%252F%252Fjira.suse.com%26cookieTime%3D1766463876elayState%3D9fad1e36-be03-45bb-983f-bbd3f4c64b7c%26cookieTime%3D1762358357 . An update has been issued for a significant libnbd vulnerability affecting openSUSE Leap, addressing failures caused by irregular block dimensions.. openSUSE Update, libnbd Security Fix, moderate Issue, openSUSE Leap, software Patch. . LinuxSecurity.com Team
Important: mariadb:10.5 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5683", "synopsis": "Important: mariadb:10.5 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for mariadb, galera, module.Judy, module.mariadb, Judy, module.galera.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. \n\nThe following packages have been upgraded to a later upstream version: galera\n(26.4.14), mariadb (10.5.22).\n\nSecurity Fix(es):\n\n* mariadb: node crashes with Transport endpoint is not connected mysqld got signal 6 (CVE-2023-5157)\n\n* mariadb: use-after-poison in prepare_inplace_add_virtual in handler0alter.cc (CVE-2022-32081)\n\n* mariadb: assertion failure at table-> get_ref_count() == 0 in dict0dict.cc (CVE-2022-32082)\n\n* mariadb: segmentation fault via the component sub_select (CVE-2022-32084)\n\n* mariadb: server crash in st_select_lex_unit::exclude_level (CVE-2022-32089)\n\n* mariadb: server crash in JOIN_CACHE::free or in copy_fields (CVE-2022-32091)\n\n* mariadb: compress_write() fails to release mutex on failure (CVE-2022-38791)\n\n* mariadb: NULL pointer dereference in spider_db_mbase::print_warnings() (CVE-2022-47015)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2106028", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106028", "description": ""}, {"ticket": "2106030", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106030", "description": ""}, {"ticket": "2106034", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2106034", "description": ""}, {"ticket": "2106035", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106035", "description": ""}, {"ticket": "2106042", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106042", "description": ""}, {"ticket": "2130105", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2130105", "description": ""}, {"ticket": "2163609", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2163609", "description": ""}, {"ticket": "2240246", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2240246", "description": ""}], "cves": [{"name": "CVE-2022-32081", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32081", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32082", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32082", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32084", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32084", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32089", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32089", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32091", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32091", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-38791", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-38791", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-47015", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-47015","cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-5157", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5157", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-10-14T02:08:04.577837Z", "rpms": {"Rocky Linux 8": {"nvras": ["galera-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "galera-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.src.rpm", "galera-debuginfo-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "galera-debugsource-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.src.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "mariadb-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.src.rpm", "mariadb-backup-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-backup-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-common-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-debugsource-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-devel-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-embedded-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-embedded-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-embedded-devel-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-errmsg-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-gssapi-server-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-gssapi-server-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-oqgraph-engine-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm","mariadb-oqgraph-engine-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-pam-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-pam-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-galera-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-utils-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-utils-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-test-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-test-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important announcement regarding MariaDB on Rocky Linux tackling crucial security vulnerabilities. Discover details about the enhancements and their implications.. Rocky Linux Security Advisory, MariaDB Crash Issues, Important Security Fixes. . Severity: Important. LinuxSecurity.com Team
Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing to crash the server, information disclosure or Cross-Site-Scripting attacks. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3538-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Tobias Frost August 22, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : zabbix Version : 1:4.0.4+dfsg-1+deb10u2 CVE ID : CVE-2013-7484 CVE-2019-17382 CVE-2022-35229 CVE-2022-43515 CVE-2023-29450 CVE-2023-29451 CVE-2023-29454 CVE-2023-29455 CVE-2023-29456 CVE-2023-29457 Debian Bug : 1026847 Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing to crash the server, information disclosure or Cross-Site-Scripting attacks. Important Notices: To mitigate CVE-2019-17382, on existing installations, the guest account needs to be manually disabled, for example by disabling the the "Guest group" in the UI: Administration -> User groups -> Guests -> Untick Enabled This update also fixes a regression with CVE-2022-35229, which broke the possiblity to edit and add discovery rules in the UI. CVE-2013-7484 Zabbix before version 4.4.0alpha2 stores credentials in the "users" table with the password hash stored as a MD5 hash, which is a known insecure hashing method. Furthermore, no salt is used with the hash. CVE-2019-17382 (Disputed, not seen by upstream as not a security issue) An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password(i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin. CVE-2022-35229 An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. CVE-2022-43515 Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range. CVE-2023-29450 JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data. CVE-2023-29451 Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy. CVE-2023-29454 A Stored or persistent cross-site scripting (XSS) vulnerability was found on âUsersâ section in âMediaâ tab in âSend toâ form field. When new media is created with malicious code included into field âSend toâ then it will execute when editing the same media. CVE-2023-29455 A Reflected XSS attacks, also known as non-persistent attacks, was found where an attacker can pass malicious code as GET request to graph.php and system will save it and will execute when current graph page is opened. CVE-2023-29456 URL validation scheme receives input from a user and thenparses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards. CVE-2023-29457 A Reflected XSS attacks, also known as non-persistent attacks, was found where XSS session cookies could be revealed, enabling a perpetrator to impersonate valid users and abuse their private accounts. For Debian 10 buster, these problems have been fixed in version 1:4.0.4+dfsg-1+deb10u2. We recommend that you upgrade your zabbix packages. For the detailed security status of zabbix please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zabbix Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several vulnerabilities identified in Zabbix according to Debian LTS Advisory DLA-3538-1, advising immediate upgrades to avert potential attacks.. Debian Security, Zabbix Exploits, Cyber Threats. . LinuxSecurity.com Team
Several flaws were found in freeradius, a high-performance and highly configurable RADIUS server. CVE-2022-41859 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3342-1
Get the latest Linux and open source security news straight to your inbox.