The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1305-1 Container Tags : suse/sles12sp4:26.594 , suse/sles12sp4:latest Container Release : 26.594 Severity : moderate Type : security References : 1210411 1210412 CVE-2023-28484 CVE-2023-29469 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2054-1 Released: Thu Apr 27 11:31:36 2023 Summary: Security update for libxml2 Type: security Severity: moderate References: 1210411,1210412,CVE-2023-28484,CVE-2023-29469 This update for libxml2 fixes the following issues: - CVE-2023-29469: Fixed inconsistent result when hashing empty strings (bsc#1210412). - CVE-2023-28484: Fixed NULL pointer dereference in xmlSchemaFixupComplexType (bsc#1210411). The following package changes have been done: - base-container-licenses-3.0-1.344 updated - container-suseconnect-2.0.0-1.227 updated - libxml2-2-2.9.4-46.62.1 updated . SUSE Container Update Notification: suse/sles12sp4 includes essential patches resolving vulnerabilities in libxml2.. SUSE Container Update, libxml2 Fix, security update, SUSE Security, container patches. . LinuxSecurity.com Team
The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1186-1 Container Tags : suse/sles12sp4:26.591 , suse/sles12sp4:latest Container Release : 26.591 Severity : moderate Type : security References : 1209873 1209878 CVE-2023-0465 CVE-2023-0466 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1914-1 Released: Wed Apr 19 14:24:23 2023 Summary: Security update for openssl-1_0_0 Type: security Severity: moderate References: 1209873,1209878,CVE-2023-0465,CVE-2023-0466 This update for openssl-1_0_0 fixes the following issues: - CVE-2023-0465: Invalid certificate policies in leaf certificates were silently ignored (bsc#1209878). - CVE-2023-0466: Certificate policy check were not enabled (bsc#1209873). The following package changes have been done: - base-container-licenses-3.0-1.343 updated - container-suseconnect-2.0.0-1.226 updated - libopenssl1_0_0-1.0.2p-3.72.1 updated - openssl-1_0_0-1.0.2p-3.72.1 updated . SUSE Container Update Notification: suse/sles12sp4 comprises crucial fixes and enhancements for improved security.. suse sles12sp4 updates security patches container. . LinuxSecurity.com Team
The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:682-1 Container Tags : suse/sles12sp4:26.444 , suse/sles12sp4:latest Container Release : 26.444 Severity : important Type : security References : 1196490 CVE-2022-23308 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1308-1 Released: Fri Apr 22 16:07:40 2022 Summary: Security update for libxml2 Type: security Severity: important References: 1196490,CVE-2022-23308 This update for libxml2 fixes the following issues: - CVE-2022-23308: Fixed use-after-free of ID and IDREF attributes. (bsc#1196490) The following package changes have been done: - base-container-licenses-3.0-1.282 updated - container-suseconnect-2.0.0-1.173 updated - libxml2-2-2.9.4-46.49.1 updated . The SUSE Container Update notice outlines crucial patches for suse/sles12sp4, focusing on vulnerabilities that pose security risks.. SUSE Updates, Libxml2 Security, Container Advisory, SUSE Patch Management. . Severity: Important. LinuxSecurity.com Team
The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:279-1 Container Tags : suse/sles12sp4:26.424 , suse/sles12sp4:latest Container Release : 26.424 Severity : important Type : security References : 1196025 1196249 1196784 1196877 CVE-2022-0778 CVE-2022-25236 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:842-1 Released: Tue Mar 15 11:32:49 2022 Summary: Security update for expat Type: security Severity: important References: 1196025,1196784,CVE-2022-25236 This update for expat fixes the following issues: - Fixed a regression caused by the patch for CVE-2022-25236 (bsc#1196784). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:857-1 Released: Tue Mar 15 19:33:24 2022 Summary: Security update for openssl-1_0_0 Type: security Severity: important References: 1196249,1196877,CVE-2022-0778 This update for openssl-1_0_0 fixes the following issues: - CVE-2022-0778: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (bsc#1196877). - Allow CRYPTO_THREADID_set_callback to be called with NULL parameter (bsc#1196249). The following package changes have been done: - base-container-licenses-3.0-1.273 updated - container-suseconnect-2.0.0-1.165 updated - libexpat1-2.1.0-21.22.1 updated - libopenssl1_0_0-1.0.2p-3.48.1 updated - openssl-1_0_0-1.0.2p-3.48.1 updated . SUSE Container Security Notice SUSE-CU-2022:280-1 addresses urgent updates regarding glibc and curl security flaws.. suse container update, security patches, expat update, openssl issues. . Severity: Important.LinuxSecurity.com Team
The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:219-1 Container Tags : suse/sles12sp4:26.298 , suse/sles12sp4:latest Container Release : 26.298 Severity : moderate Type : security References : 1175109 1177976 1179398 1179399 1179593 1183933 1186114 CVE-2020-8231 CVE-2020-8284 CVE-2020-8285 CVE-2020-8286 CVE-2021-22876 CVE-2021-22898 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1786-1 Released: Thu May 27 16:45:41 2021 Summary: Security update for curl Type: security Severity: moderate References: 1175109,1177976,1179398,1179399,1179593,1183933,1186114,CVE-2020-8231,CVE-2020-8284,CVE-2020-8285,CVE-2020-8286,CVE-2021-22876,CVE-2021-22898 This update for curl fixes the following issues: - CVE-2021-22898: TELNET stack contents disclosure (bsc#1186114) - CVE-2021-22876: The automatic referer leaks credentials (bsc#1183933) - CVE-2020-8286: Inferior OCSP verification (bsc#1179593) - CVE-2020-8285: FTP wildcard stack overflow (bsc#1179399) - CVE-2020-8284: Trusting FTP PASV responses (bsc#1179398) - CVE-2020-8231: libcurl will pick and use the wrong connection with multiple requests with libcurl's multi API and the 'CURLOPT_CONNECT_ONLY' option (bsc#1175109) - Fix: SFTP uploads result in empty uploaded files (bsc#1177976) . Notice of security updates for the SUSE container suse/sles12sp4, which incorporates several patch corrections and enhanced security measures.. Container Update, SUSE Security Update, SLE Patch, SLES12SP4 Advisory. . LinuxSecurity.com Team
The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:104-1 Container Tags : suse/sles12sp4:26.273 , suse/sles12sp4:latest Container Release : 26.273 Severity : important Type : security References : 1178386 1179694 1179721 1184034 CVE-2020-27618 CVE-2020-29562 CVE-2020-29573 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1165-1 Released: Tue Apr 13 14:03:17 2021 Summary: Security update for glibc Type: security Severity: important References: 1178386,1179694,1179721,1184034,CVE-2020-27618,CVE-2020-29562,CVE-2020-29573 This update for glibc fixes the following issues: - CVE-2020-27618: Accept redundant shift sequences in IBM1364 (bsc#1178386) - CVE-2020-29562: Fix incorrect UCS4 inner loop bounds (bsc#1179694) - CVE-2020-29573: Harden printf against non-normal long double values (bsc#1179721) - Check vector support in memmove ifunc-selector (bsc#1184034) . Enhancements for opensuse/sles12sp4 incorporate vital updates to mitigate significant vulnerabilities and ensure system reliability.. SUSE, SLES12SP4, Security Patches, Container Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1368-1 Rating: important References: #1134524 Cross-References: CVE-2019-5021 Affected Products: SUSE Linux Enterprise Module for Containers 12 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues: - CVE-2019-5021: Include an invalidated root password by default, not an empty one (bsc#1134524) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Containers 12: zypper in -t patch SUSE-SLE-Module-Containers-12-2019-1368=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-1368=1 Package List: - SUSE Linux Enterprise Module for Containers 12 (ppc64le s390x x86_64): suse-sles12sp3-image-2.0.2-22.1 - SUSE Linux Enterprise Module for Basesystem 15 (noarch): system-user-root-20190513-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-5021.html https://bugzilla.suse.com/1134524 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.