An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for lasso ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2589-1 Rating: important References: #1186768 Cross-References: CVE-2021-28091 CVSS scores: CVE-2021-28091 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2021-28091 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for lasso fixes the following issues: - CVE-2021-28091: Fixed XML signature wrapping vulnerability when parsing SAML responses. (bsc#1186768) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2589=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-2589=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): liblasso-devel-2.6.1-8.7.2 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): liblasso3-2.6.1-8.7.2 python3-lasso-2.6.1-8.7.2 References: https://www.suse.com/security/cve/CVE-2021-28091.html https://bugzilla.suse.com/1186768 . SUSE Security Patch: Critical resolution for lasso related to XML signature vulnerabilities identified as CVE-2021-28091.. SUSE Security Update,lasso vulnerability,software development kit,XML signature issue,12-SP5advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for subversion ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0424-1 Rating: important References: #1181687 Cross-References: CVE-2020-17525 CVSS scores: CVE-2020-17525 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for subversion fixes the following issues: - CVE-2020-17525: A null-pointer-dereference has been found in mod_authz_svn that results in a remote unauthenticated Denial-of-Service in some server configurations (bsc#1181687). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-424=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libsvn_auth_gnome_keyring-1-0-1.10.6-3.3.1 libsvn_auth_gnome_keyring-1-0-debuginfo-1.10.6-3.3.1 subversion-1.10.6-3.3.1 subversion-debuginfo-1.10.6-3.3.1 subversion-debugsource-1.10.6-3.3.1 subversion-devel-1.10.6-3.3.1 subversion-perl-1.10.6-3.3.1 subversion-perl-debuginfo-1.10.6-3.3.1 subversion-python-1.10.6-3.3.1 subversion-python-debuginfo-1.10.6-3.3.1 subversion-server-1.10.6-3.3.1 subversion-server-debuginfo-1.10.6-3.3.1 subversion-tools-1.10.6-3.3.1 subversion-tools-debuginfo-1.10.6-3.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (noarch): subversion-bash-completion-1.10.6-3.3.1 References: https://www.suse.com/security/cve/CVE-2020-17525.html https://bugzilla.suse.com/1181687 . SUSE has released a security update to tackle a denial-of-service vulnerability in subversion impacting SDK 12-SP5, categorized with critical ratings.. SUSE Update, Subversion Patch, Security Issue, DoS, SDK 12-SP5. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1684-1 Rating: important References: #1138872 Cross-References: CVE-2019-11708 Affected Products: SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 SUSE Enterprise Storage 5 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for MozillaFirefox fixes the following issues: - Mozilla Firefox Firefox 60.7.2 MFSA 2019-19 (bsc#1138872) - CVE-2019-11708: Fix sandbox escape using Prompt:Open. * Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parentprocesses could result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2019-1684=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-1684=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2019-1684=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-1684=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-1684=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2019-1684=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-1684=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-1684=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2019-1684=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-1684=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-1684=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-1684=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-1684=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-1684=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-1684=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2019-1684=1 - SUSE Linux Enterprise Desktop 12-SP5: zypper in -t patch SUSE-SLE-DESKTOP-12-SP5-2019-1684=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-1684=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-1684=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2019-1684=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-1684=1 Package List: - SUSE OpenStack Cloud 8 (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE OpenStack Cloud 7 (s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Desktop 12-SP5 (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Enterprise Storage 5 (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 - SUSE Enterprise Storage 4 (x86_64): MozillaFirefox-60.7.2-109.80.1 MozillaFirefox-debuginfo-60.7.2-109.80.1 MozillaFirefox-debugsource-60.7.2-109.80.1 MozillaFirefox-devel-60.7.2-109.80.1 MozillaFirefox-translations-common-60.7.2-109.80.1 References: https://www.suse.com/security/cve/CVE-2019-11708.html https://bugzilla.suse.com/1138872 _______________________________________________ sle-security-updates mailing list
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for gcc43 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1498-1 Rating: moderate References: #1086069 #1092807 Cross-References: CVE-2017-5715 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for gcc43 fixes the following issues: This update adds support for "expolines" on s390x, allowing fixing CVE-2017-5715 in a more lightweight fashion. (bsc#1086069) The option flags are the same as for the x86 retpolines. A compiler crash when building userland packages with x86 retpolines was fixed. (bsc#1092807) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-gcc43-13639=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-gcc43-13639=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-gcc43-13639=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-gcc43-13639=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-gcc43-13639=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -tpatch dbgsp3-gcc43-13639=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): cpp43-4.3.4_20091019-37.9.1 gcc43-fortran-4.3.4_20091019-37.9.1 gcc43-obj-c++-4.3.4_20091019-37.9.1 gcc43-objc-4.3.4_20091019-37.9.1 libobjc43-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64): gcc43-fortran-32bit-4.3.4_20091019-37.9.1 gcc43-objc-32bit-4.3.4_20091019-37.9.1 libobjc43-32bit-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 x86_64): gcc43-ada-4.3.4_20091019-37.9.1 libada43-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): cpp43-4.3.4_20091019-37.9.1 gcc43-4.3.4_20091019-37.9.1 gcc43-c++-4.3.4_20091019-37.9.1 gcc43-info-4.3.4_20091019-37.9.1 gcc43-locale-4.3.4_20091019-37.9.1 libstdc++43-devel-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): gcc43-32bit-4.3.4_20091019-37.9.1 libstdc++43-devel-32bit-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): cpp43-4.3.4_20091019-37.9.1 gcc43-4.3.4_20091019-37.9.1 gcc43-c++-4.3.4_20091019-37.9.1 gcc43-info-4.3.4_20091019-37.9.1 gcc43-locale-4.3.4_20091019-37.9.1 libstdc++43-devel-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (s390x x86_64): gcc43-32bit-4.3.4_20091019-37.9.1 libstdc++43-devel-32bit-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): cpp43-4.3.4_20091019-37.9.1 gcc43-4.3.4_20091019-37.9.1 gcc43-c++-4.3.4_20091019-37.9.1 gcc43-info-4.3.4_20091019-37.9.1 gcc43-locale-4.3.4_20091019-37.9.1 libstdc++43-devel-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): gcc43-debuginfo-4.3.4_20091019-37.9.1 gcc43-debugsource-4.3.4_20091019-37.9.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): gcc43-debuginfo-4.3.4_20091019-37.9.1 gcc43-debugsource-4.3.4_20091019-37.9.1 References: https://www.suse.com/security/cve/CVE-2017-5715.html https://bugzilla.suse.com/1086069 https://bugzilla.suse.com/1092807 . SUSE Security Patch for gcc43 resolves a flaw in SUSE Software Development Kit and server offerings.. SUSE Security Update,gcc43,vulnerability fix,software development kit,server security. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. SUSE Security Update: Security update for expat ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:1508-1 Rating: important References: #979441 #980391 Cross-References: CVE-2015-1283 CVE-2016-0718 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP1 SUSE Linux Enterprise Software Development Kit 12 SUSE Linux Enterprise Server 12-SP1 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Desktop 12-SP1 SUSE Linux Enterprise Desktop 12 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for expat fixes the following issues: Security issue fixed: - CVE-2016-0718: Fix Expat XML parser that mishandles certain kinds of malformed input documents. (bsc#979441) - CVE-2015-1283: Fix multiple integer overflows. (bnc#980391) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP1: zypper in -t patch SUSE-SLE-SDK-12-SP1-2016-898=1 - SUSE Linux Enterprise Software Development Kit 12: zypper in -t patch SUSE-SLE-SDK-12-2016-898=1 - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-898=1 - SUSE Linux Enterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2016-898=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2016-898=1 - SUSE Linux Enterprise Desktop 12: zypper in -t patchSUSE-SLE-DESKTOP-12-2016-898=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP1 (ppc64le s390x x86_64): expat-debuginfo-2.1.0-17.1 expat-debugsource-2.1.0-17.1 libexpat-devel-2.1.0-17.1 - SUSE Linux Enterprise Software Development Kit 12 (ppc64le s390x x86_64): expat-debuginfo-2.1.0-17.1 expat-debugsource-2.1.0-17.1 libexpat-devel-2.1.0-17.1 - SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64): expat-2.1.0-17.1 expat-debuginfo-2.1.0-17.1 expat-debugsource-2.1.0-17.1 libexpat1-2.1.0-17.1 libexpat1-debuginfo-2.1.0-17.1 - SUSE Linux Enterprise Server 12-SP1 (s390x x86_64): expat-debuginfo-32bit-2.1.0-17.1 libexpat1-32bit-2.1.0-17.1 libexpat1-debuginfo-32bit-2.1.0-17.1 - SUSE Linux Enterprise Server 12 (ppc64le s390x x86_64): expat-2.1.0-17.1 expat-debuginfo-2.1.0-17.1 expat-debugsource-2.1.0-17.1 libexpat1-2.1.0-17.1 libexpat1-debuginfo-2.1.0-17.1 - SUSE Linux Enterprise Server 12 (s390x x86_64): expat-debuginfo-32bit-2.1.0-17.1 libexpat1-32bit-2.1.0-17.1 libexpat1-debuginfo-32bit-2.1.0-17.1 - SUSE Linux Enterprise Desktop 12-SP1 (x86_64): expat-2.1.0-17.1 expat-debuginfo-2.1.0-17.1 expat-debuginfo-32bit-2.1.0-17.1 expat-debugsource-2.1.0-17.1 libexpat1-2.1.0-17.1 libexpat1-32bit-2.1.0-17.1 libexpat1-debuginfo-2.1.0-17.1 libexpat1-debuginfo-32bit-2.1.0-17.1 - SUSE Linux Enterprise Desktop 12 (x86_64): expat-2.1.0-17.1 expat-debuginfo-2.1.0-17.1 expat-debuginfo-32bit-2.1.0-17.1 expat-debugsource-2.1.0-17.1 libexpat1-2.1.0-17.1 libexpat1-32bit-2.1.0-17.1 libexpat1-debuginfo-2.1.0-17.1 libexpat1-debuginfo-32bit-2.1.0-17.1 References: https://www.suse.com/security/cve/CVE-2015-1283.html https://www.suse.com/security/cve/CVE-2016-0718.html https://bugzilla.suse.com/979441 https://bugzilla.suse.com/980391 . SUSE Security Patch for libpng addresses critical flaws, fostering enhanced system safety.. SUSE Security Update, expat vulnerabilities, important software patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes 9 vulnerabilities is now available. It An update that fixes 9 vulnerabilities is now available. It An update that fixes 9 vulnerabilities is now available. It includes four new package versions. includes four new package versions.. SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2014:1385-1 Rating: important References: #900941 Cross-References: CVE-2014-1574 CVE-2014-1575 CVE-2014-1576 CVE-2014-1577 CVE-2014-1578 CVE-2014-1581 CVE-2014-1583 CVE-2014-1585 CVE-2014-1586 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise Server 11 SP3 for VMware SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Server 11 SP2 LTSS SUSE Linux Enterprise Desktop 11 SP3 ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. It includes four new package versions. Description: This version update of Mozilla Firefox to 31.2.0ESR brings improvements, stability fixes and also security fixes for the following CVEs: CVE-2014-1574, CVE-2014-1575, CVE-2014-1576 ,CVE-2014-1577, CVE-2014-1578, CVE-2014-1581, CVE-2014-1583, CVE-2014-1585, CVE-2014-1586 It also disables SSLv3 by default to mitigate the protocol downgrade attack known as POODLE. Security Issues: * CVE-2014-1574 * CVE-2014-1575 * CVE-2014-1576 * CVE-2014-1577 * CVE-2014-1578 * CVE-2014-1581 * CVE-2014-1583 * CVE-2014-1585 * CVE-2014-1586 Indications: Everybody should update. Patch Instructions: To install this SUSE SecurityUpdate use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP3: zypper in -t patch sdksp3-firefox31-201411-9935 - SUSE Linux Enterprise Server 11 SP3 for VMware: zypper in -t patch slessp3-firefox31-201411-9935 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-firefox31-201411-9935 - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-firefox31-201411-9936 - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-firefox31-201411-9935 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 3.17.2 and 4.10.7]: MozillaFirefox-devel-31.2.0esr-0.14.2 mozilla-nspr-devel-4.10.7-0.3.3 mozilla-nss-devel-3.17.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64) [New Version: 3.17.2,31.2.0esr and 4.10.7]: MozillaFirefox-31.2.0esr-0.14.2 MozillaFirefox-branding-SLES-for-VMware-31.0-0.3.1 MozillaFirefox-translations-31.2.0esr-0.14.2 libfreebl3-3.17.2-0.8.1 libsoftokn3-3.17.2-0.8.1 mozilla-nspr-4.10.7-0.3.3 mozilla-nss-3.17.2-0.8.1 mozilla-nss-tools-3.17.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 for VMware (x86_64) [New Version: 3.17.2 and 4.10.7]: libfreebl3-32bit-3.17.2-0.8.1 libsoftokn3-32bit-3.17.2-0.8.1 mozilla-nspr-32bit-4.10.7-0.3.3 mozilla-nss-32bit-3.17.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 3.17.2,31.0,31.2.0esr and 4.10.7]: MozillaFirefox-31.2.0esr-0.14.2 MozillaFirefox-branding-SLED-31.0-0.8.1 MozillaFirefox-translations-31.2.0esr-0.14.2 libfreebl3-3.17.2-0.8.1 libsoftokn3-3.17.2-0.8.1 mozilla-nspr-4.10.7-0.3.3 mozilla-nss-3.17.2-0.8.1 mozilla-nss-tools-3.17.2-0.8.1 - SUSE LinuxEnterprise Server 11 SP3 (ppc64 s390x x86_64) [New Version: 3.17.2 and 4.10.7]: libfreebl3-32bit-3.17.2-0.8.1 libsoftokn3-32bit-3.17.2-0.8.1 mozilla-nspr-32bit-4.10.7-0.3.3 mozilla-nss-32bit-3.17.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 (ia64) [New Version: 3.17.2 and 4.10.7]: libfreebl3-x86-3.17.2-0.8.1 libsoftokn3-x86-3.17.2-0.8.1 mozilla-nspr-x86-4.10.7-0.3.3 mozilla-nss-x86-3.17.2-0.8.1 - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64) [New Version: 3.17.2,31.2.0esr and 4.10.7]: MozillaFirefox-31.2.0esr-0.9.1 MozillaFirefox-branding-SLED-31.0-0.3.1 MozillaFirefox-translations-31.2.0esr-0.9.1 libfreebl3-3.17.2-0.3.1 mozilla-nspr-4.10.7-0.3.3 mozilla-nspr-devel-4.10.7-0.3.3 mozilla-nss-3.17.2-0.3.1 mozilla-nss-devel-3.17.2-0.3.1 mozilla-nss-tools-3.17.2-0.3.1 - SUSE Linux Enterprise Server 11 SP2 LTSS (s390x x86_64) [New Version: 3.17.2 and 4.10.7]: libfreebl3-32bit-3.17.2-0.3.1 mozilla-nspr-32bit-4.10.7-0.3.3 mozilla-nss-32bit-3.17.2-0.3.1 - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 3.17.2,31.0,31.2.0esr and 4.10.7]: MozillaFirefox-31.2.0esr-0.14.2 MozillaFirefox-branding-SLED-31.0-0.8.1 MozillaFirefox-translations-31.2.0esr-0.14.2 libfreebl3-3.17.2-0.8.1 libsoftokn3-3.17.2-0.8.1 mozilla-nspr-4.10.7-0.3.3 mozilla-nss-3.17.2-0.8.1 mozilla-nss-tools-3.17.2-0.8.1 - SUSE Linux Enterprise Desktop 11 SP3 (x86_64) [New Version: 3.17.2 and 4.10.7]: libfreebl3-32bit-3.17.2-0.8.1 libsoftokn3-32bit-3.17.2-0.8.1 mozilla-nspr-32bit-4.10.7-0.3.3 mozilla-nss-32bit-3.17.2-0.8.1 References: https://www.suse.com/security/cve/CVE-2014-1574.html https://www.suse.com/security/cve/CVE-2014-1575.html https://www.suse.com/security/cve/CVE-2014-1576.html https://www.suse.com/security/cve/CVE-2014-1577.html https://www.suse.com/security/cve/CVE-2014-1578.html https://www.suse.com/security/cve/CVE-2014-1581.html https://www.suse.com/security/cve/CVE-2014-1583.html https://www.suse.com/security/cve/CVE-2014-1585.html https://www.suse.com/security/cve/CVE-2014-1586.html https://bugzilla.suse.com/show_bug.cgi?id=900941 https://scc.suse.com:443/patches/ https://scc.suse.com:443/patches/ . SUSE Security Update: Security update for MozillaFirefox ___________________________________________. update, fixes, vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.. SUSE Security Update: Security update for IBM Java 1.4.2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:1490-1 Rating: important References: #758651 #788750 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 10 SP4 SUSE Linux Enterprise Java 11 SP2 SUSE Linux Enterprise Java 10 SP4 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: IBM Java 1.4.2 has been updated to SR13-FP14 which fixes bugs and security issues. More information can be found on: [:// CVEs fixed: CVE-2012-3216,CVE-2012-5073,CVE-2012-5083,CVE-2012-5083,CVE- 2012-1531,CVE-2012-5081,CVE-2012-5084,CVE-2012-5079 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-java-1_4_2-ibm-7043 - SUSE Linux Enterprise Server 11 SP2 for VMware: zypper in -t patch slessp2-java-1_4_2-ibm-7043 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-java-1_4_2-ibm-7043 - SUSE Linux Enterprise Java 11 SP2: zypper in -t patch slejsp2-java-1_4_2-ibm-7043 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64): java-1_4_2-ibm-devel-1.4.2_sr13.14-0.2.1 - SUSE LinuxEnterprise Software Development Kit 11 SP2 (i586 x86_64): java-1_4_2-ibm-1.4.2_sr13.14-0.2.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64): java-1_4_2-ibm-1.4.2_sr13.14-0.2.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586): java-1_4_2-ibm-jdbc-1.4.2_sr13.14-0.2.1 java-1_4_2-ibm-plugin-1.4.2_sr13.14-0.2.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64): java-1_4_2-ibm-1.4.2_sr13.14-0.2.1 - SUSE Linux Enterprise Server 11 SP2 (i586): java-1_4_2-ibm-jdbc-1.4.2_sr13.14-0.2.1 java-1_4_2-ibm-plugin-1.4.2_sr13.14-0.2.1 - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64): java-1_4_2-ibm-1.4.2_sr13.14-0.5.1 java-1_4_2-ibm-devel-1.4.2_sr13.14-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (i586 ppc): java-1_4_2-ibm-jdbc-1.4.2_sr13.14-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (i586): java-1_4_2-ibm-plugin-1.4.2_sr13.14-0.5.1 - SUSE Linux Enterprise Java 11 SP2 (i586 ppc64 s390x x86_64): java-1_4_2-ibm-1.4.2_sr13.14-0.2.1 - SUSE Linux Enterprise Java 11 SP2 (i586): java-1_4_2-ibm-jdbc-1.4.2_sr13.14-0.2.1 java-1_4_2-ibm-plugin-1.4.2_sr13.14-0.2.1 - SUSE Linux Enterprise Java 10 SP4 (i586 ia64 ppc s390x x86_64): java-1_4_2-ibm-1.4.2_sr13.14-0.5.1 java-1_4_2-ibm-devel-1.4.2_sr13.14-0.5.1 - SUSE Linux Enterprise Java 10 SP4 (i586 ppc): java-1_4_2-ibm-jdbc-1.4.2_sr13.14-0.5.1 - SUSE Linux Enterprise Java 10 SP4 (i586): java-1_4_2-ibm-plugin-1.4.2_sr13.14-0.5.1 References: . Red Hat Security Patch improves overall stability with updates for OpenJDK 8, maintaining consistent functionality and fortifying defenses.. IBM Java Update, SUSE Security, Important Fixes, Java Release. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.