The container bci/golang was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2121-1 Container Tags : bci/golang:1.20 , bci/golang:1.20-1.5.3 , bci/golang:latest , bci/golang:stable , bci/golang:stable-1.5.3 Container Release : 5.3 Severity : important Type : security References : 1201627 1207534 1211430 CVE-2022-4304 CVE-2023-2650 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 29171 Released: Tue Jun 20 12:29:00 2023 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1201627,1207534,1211430,CVE-2022-4304,CVE-2023-2650 This update for openssl-1_1 fixes the following issues: - CVE-2023-2650: Fixed possible denial of service translating ASN.1 object identifiers (bsc#1211430). - CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption. The previous fix for this timing side channel turned out to cause a severe 2-3x performance regression in the typical use case (bsc#1207534). - Update further expiring certificates that affect tests (bsc#1201627) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2625-1 Released: Fri Jun 23 17:16:11 2023 Summary: Recommended update for gcc12 Type: recommended Severity: moderate References: This update for gcc12 fixes the following issues: - Update to GCC 12.3 release, 0c61aa720e62f1baf0bfd178e283, git1204 * includes regression and other bug fixes - Speed up builds with --enable-link-serialization. - Update embedded newlib to version 4.2.0 The following package changes have been done: - libgcc_s1-12.3.0+git1204-150000.1.10.1 updated -libstdc++6-12.3.0+git1204-150000.1.10.1 updated - libopenssl1_1-1.1.1l-150500.17.6.1 updated - libopenssl1_1-hmac-1.1.1l-150500.17.6.1 updated - libatomic1-12.3.0+git1204-150000.1.10.1 updated - libgomp1-12.3.0+git1204-150000.1.10.1 updated - libitm1-12.3.0+git1204-150000.1.10.1 updated - liblsan0-12.3.0+git1204-150000.1.10.1 updated - container:sles15-image-15.0.0-36.5.7 updated . SUSE enhances bci/ruby with critical security fixes targeting information leaks and memory management vulnerabilities.. SUSE Container,bci/golang,security update,software patches. . Severity: Important. LinuxSecurity.com Team
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1618-1 Container Tags : suse/sle-micro/5.4/toolbox:12.1 , suse/sle-micro/5.4/toolbox:12.1-4.2.31 , suse/sle-micro/5.4/toolbox:latest Container Release : 4.2.31 Severity : important Type : security References : 1127591 1195633 1203141 1207410 1207712 1208329 1209406 1210081 1210870 1211144 1211230 1211231 1211232 1211233 CVE-2023-28319 CVE-2023-28320 CVE-2023-28321 CVE-2023-28322 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2209-1 Released: Tue May 16 10:34:54 2023 Summary: Recommended update for gdb Type: recommended Severity: moderate References: 1207712,1210081 This update for gdb fixes the following issues: - Fix license of gdb to be GPLv3, due to a mistake the testsuite results license was used (bsc#1210081). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2224-1 Released: Wed May 17 09:53:54 2023 Summary: Security update for curl Type: security Severity: important References: 1211230,1211231,1211232,1211233,CVE-2023-28319,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322 This update for curl adds the following feature: Update to version 8.0.1 (jsc#PED-2580) - CVE-2023-28319: use-after-free in SSH sha256 fingerprint check (bsc#1211230). - CVE-2023-28320: siglongjmp race condition (bsc#1211231). - CVE-2023-28321: IDN wildcard matching (bsc#1211232). - CVE-2023-28322: POST-after-PUT confusion(bsc#1211233). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2237-1 Released: Wed May 17 17:10:07 2023 Summary: Recommended update for vim Type: recommended Severity: moderate References: 1211144 This update for vim fixes the following issues: * Make xxd conflict with the previous vim packages to avoid a file conflict during migration (bsc#1211144) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2240-1 Released: Wed May 17 19:56:54 2023 Summary: Recommended update for systemd Type: recommended Severity: moderate References: 1203141,1207410 This update for systemd fixes the following issues: - udev-rules: fix nvme symlink creation on namespace changes (bsc#1207410) - Optimize when hundred workers claim the same symlink with the same priority (bsc#1203141) - Add nss-resolve and systemd-network to Packagehub-Subpackages (MSC-626) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2245-1 Released: Thu May 18 17:01:47 2023 Summary: Recommended update for libzypp, zypper Type: recommended Severity: moderate References: 1127591,1195633,1208329,1209406,1210870 This update for libzypp, zypper fixes the following issues: - Installing local RPM packages fails if /usr/bin/find is not installed (bsc#1195633) - multicurl: propagate ssl settings stored in repo url (bsc#1127591) - MediaCurl: Fix endless loop if wrong credentials are stored in credentials.cat (bsc#1210870) - zypp.conf: Introduce 'download.connect_timeout' [60 sec.] (bsc#1208329) - Teach MediaNetwork to retry on HTTP2 errors. - Fix selecting installed patterns from picklist (bsc#1209406) - man: better explanation of --priority The following package changes have been done: - gdb-12.1-150400.15.9.1 updated - libcurl4-8.0.1-150400.5.23.1 updated - libsolv-tools-0.7.24-150400.3.6.4 updated - libsystemd0-249.16-150400.8.28.3 updated - libudev1-249.16-150400.8.28.3 updated -libzypp-17.31.11-150400.3.25.2 updated - systemd-249.16-150400.8.28.3 updated - vim-data-common-9.0.1443-150000.5.43.1 updated - vim-9.0.1443-150000.5.43.1 updated - xxd-9.0.1443-150000.5.43.1 updated - zypper-1.14.60-150400.3.21.2 updated - container:sles15-image-15.0.0-27.14.63 updated . SUSE Container Update Notification for suse/sle-micro/5.4/shell with critical security enhancements and fixes.. SUSE Container Security, Toolbox Update, Software Patches, Security Advisory. . Severity: Important. LinuxSecurity.com Team
The container bci/nodejs was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2173-1 Container Tags : bci/node:14 , bci/node:14-33.25 , bci/nodejs:14 , bci/nodejs:14-33.25 Container Release : 33.25 Severity : moderate Type : security References : 1193951 CVE-2020-21913 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3142-1 Released: Wed Sep 7 09:54:18 2022 Summary: Security update for icu Type: security Severity: moderate References: 1193951,CVE-2020-21913 This update for icu fixes the following issues: - CVE-2020-21913: Fixed a memory safetey issue that could lead to use after free (bsc#1193951). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3215-1 Released: Thu Sep 8 15:58:27 2022 Summary: Recommended update for rpm Type: recommended Severity: moderate References: This update for rpm fixes the following issues: - Support Ed25519 RPM signatures [jsc#SLE-24714] The following package changes have been done: - rpm-ndb-4.14.3-150300.49.1 updated - libicu65_1-ledata-65.1-150200.4.5.1 updated - libicu-suse65_1-65.1-150200.4.5.1 updated - container:sles15-image-15.0.0-27.11.21 updated . SUSE Container Update Notification for bci/python incorporates fixes that enhance security and boost performance.. bci/nodejs, Container Update, security patch. . LinuxSecurity.com Team
The container bci/nodejs was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1569-1 Container Tags : bci/node:16 , bci/node:16-8.16 , bci/node:latest , bci/nodejs:16 , bci/nodejs:16-8.16 , bci/nodejs:latest Container Release : 8.16 Severity : important Type : security References : 1197718 1199140 1199232 1199232 1200334 1200855 CVE-2022-1586 CVE-2022-1586 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2360-1 Released: Tue Jul 12 12:01:39 2022 Summary: Security update for pcre2 Type: security Severity: important References: 1199232,CVE-2022-1586 This update for pcre2 fixes the following issues: - CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2361-1 Released: Tue Jul 12 12:05:01 2022 Summary: Security update for pcre Type: security Severity: important References: 1199232,CVE-2022-1586 This update for pcre fixes the following issues: - CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2406-1 Released: Fri Jul 15 11:49:01 2022 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1197718,1199140,1200334,1200855 This update for glibc fixes the following issues: - powerpc: Fix VSX register number on __strncpy_power9 (bsc#1200334) - Disable warnings due to deprecated libselinux symbols used by nss and nscd (bsc#1197718) - i386: Remove broken CAN_USE_REGISTER_ASM_EBP(bsc#1197718) - rtld: Avoid using up static TLS surplus for optimizations (bsc#1200855, BZ #25051) This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit). The following package changes have been done: - glibc-2.31-150300.31.2 updated - libcrypt1-4.4.15-150300.4.4.3 updated - libpcre1-8.45-150000.20.13.1 updated - libpcre2-8-0-10.39-150400.4.3.1 updated - container:sles15-image-15.0.0-27.11.1 updated . SUSE Container alert regarding bci/nodejs updates that tackle significant security vulnerabilities and propose essential remedies.. bci/nodejs Update, Container Security, SUSE Advisory, Nodejs Patches, Software Updates. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-0826 https://linux.oracle.com/errata/ELSA-2022-0826.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-6.0-6.0.3-4.0.1.el8_5.x86_64.rpm aspnetcore-targeting-pack-6.0-6.0.3-4.0.1.el8_5.x86_64.rpm dotnet-6.0.103-4.0.1.el8_5.x86_64.rpm dotnet-apphost-pack-6.0-6.0.3-4.0.1.el8_5.x86_64.rpm dotnet-host-6.0.3-4.0.1.el8_5.x86_64.rpm dotnet-hostfxr-6.0-6.0.3-4.0.1.el8_5.x86_64.rpm dotnet-runtime-6.0-6.0.3-4.0.1.el8_5.x86_64.rpm dotnet-sdk-6.0-6.0.103-4.0.1.el8_5.x86_64.rpm dotnet-targeting-pack-6.0-6.0.3-4.0.1.el8_5.x86_64.rpm dotnet-templates-6.0-6.0.103-4.0.1.el8_5.x86_64.rpm netstandard-targeting-pack-2.1-6.0.103-4.0.1.el8_5.x86_64.rpm aarch64: aspnetcore-runtime-6.0-6.0.3-4.0.1.el8_5.aarch64.rpm aspnetcore-targeting-pack-6.0-6.0.3-4.0.1.el8_5.aarch64.rpm dotnet-6.0.103-4.0.1.el8_5.aarch64.rpm dotnet-apphost-pack-6.0-6.0.3-4.0.1.el8_5.aarch64.rpm dotnet-host-6.0.3-4.0.1.el8_5.aarch64.rpm dotnet-hostfxr-6.0-6.0.3-4.0.1.el8_5.aarch64.rpm dotnet-runtime-6.0-6.0.3-4.0.1.el8_5.aarch64.rpm dotnet-sdk-6.0-6.0.103-4.0.1.el8_5.aarch64.rpm dotnet-targeting-pack-6.0-6.0.3-4.0.1.el8_5.aarch64.rpm dotnet-templates-6.0-6.0.103-4.0.1.el8_5.aarch64.rpm netstandard-targeting-pack-2.1-6.0.103-4.0.1.el8_5.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/dotnet6.0-6.0.103-4.0.1.el8_5.src.rpm Related CVEs: CVE-2022-24464 CVE-2022-24512 Description of changes: [6.0.103-4.0.1] - Add missing Oracle RIDs [6.0.103-4] - Rebuild against .NET 6.0.102 to pick up the correct fixes - Resolves: RHBZ#2059640 [6.0.103-3] - Update to new source release for SDK 6.0.103 and Runtime 6.0.3 - Resolves: RHBZ#2059640 [6.0.103-2] - Switch to new source release for SDK 6.0.103 and Runtime 6.0.3 - Resolves: RHBZ#2059640 [6.0.103-1] - Update to .NET SDK 6.0.103 and Runtime 6.0.3 - Resolves:RHBZ#2059640 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-0204 https://linux.oracle.com/errata/ELSA-2022-0204.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: java-11-openjdk-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm java-11-openjdk-devel-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm java-11-openjdk-headless-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm java-11-openjdk-demo-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm java-11-openjdk-javadoc-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm java-11-openjdk-javadoc-zip-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm java-11-openjdk-jmods-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm java-11-openjdk-src-11.0.14.0.9-1.0.1.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/java-11-openjdk-11.0.14.0.9-1.0.1.el7_9.src.rpm Related CVEs: CVE-2022-21248 CVE-2022-21277 CVE-2022-21282 CVE-2022-21283 CVE-2022-21291 CVE-2022-21293 CVE-2022-21294 CVE-2022-21296 CVE-2022-21299 CVE-2022-21305 CVE-2022-21340 CVE-2022-21341 CVE-2022-21360 CVE-2022-21365 CVE-2022-21366 Description of changes: [1:11.0.14.0.9-1.0.1] - link atomic for ix86 build [1:11.0.14.0.9-1] - Update to jdk-11.0.14.0+9 - Update release notes to 11.0.14.0+9 - Switch to GA mode for final release. - This tarball is embargoed until 2022-01-18 @ 1pm PT. - Resolves: rhbz#2039366 [1:11.0.14.0.8-0.1.ea] - Update to jdk-11.0.14.0+8 - Update release notes to 11.0.14.0+8 - Switch to EA mode for 11.0.14 pre-release builds. - Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le. - Rename blacklisted.certs to blocked.certs following JDK-8253866 - Resolves: rhbz#2022810 [1:11.0.14.0.8-0.1.ea] - Replaced hardcoded 11 by featurever where appropriate - Fixed comment of `for slowdebug` to correct `any debug` - Related: rhbz#2022810 _______________________________________________ El-errata mailing list
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1136-1 Rating: moderate References: #1131291 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Desktop 12-SP3 SUSE Enterprise Storage 4 SUSE CaaS Platform ALL SUSE CaaS Platform 3.0 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for openssl fixes the following issues: - Reject invalid EC point coordinates (bsc#1131291) This helps openssl using services that do not do this verification on their own. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-1136=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-1136=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-1136=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-1136=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-1136=1 - SUSELinux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-1136=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-1136=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-1136=1 - SUSE CaaS Platform ALL: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2019-1136=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): libopenssl-devel-1.0.2j-60.52.1 libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-32bit-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.52.1 libopenssl1_0_0-hmac-1.0.2j-60.52.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE OpenStack Cloud 7 (noarch): openssl-doc-1.0.2j-60.52.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libopenssl-devel-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): libopenssl-devel-1.0.2j-60.52.1 libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 libopenssl1_0_0-hmac-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE Linux Enterprise Server forSAP 12-SP2 (x86_64): libopenssl1_0_0-32bit-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.52.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.52.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (noarch): openssl-doc-1.0.2j-60.52.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): libopenssl-devel-1.0.2j-60.52.1 libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 libopenssl1_0_0-hmac-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE Linux Enterprise Server 12-SP3 (s390x x86_64): libopenssl1_0_0-32bit-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.52.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.52.1 - SUSE Linux Enterprise Server 12-SP3 (noarch): openssl-doc-1.0.2j-60.52.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): libopenssl-devel-1.0.2j-60.52.1 libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 libopenssl1_0_0-hmac-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): libopenssl1_0_0-32bit-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.52.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.52.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): openssl-doc-1.0.2j-60.52.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libopenssl-devel-1.0.2j-60.52.1 libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-32bit-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.52.1 libopenssl1_0_0-hmac-1.0.2j-60.52.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE Linux EnterpriseServer 12-SP2-BCL (noarch): openssl-doc-1.0.2j-60.52.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libopenssl-devel-1.0.2j-60.52.1 libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-32bit-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE Enterprise Storage 4 (noarch): openssl-doc-1.0.2j-60.52.1 - SUSE Enterprise Storage 4 (x86_64): libopenssl-devel-1.0.2j-60.52.1 libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-32bit-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-32bit-1.0.2j-60.52.1 libopenssl1_0_0-hmac-1.0.2j-60.52.1 libopenssl1_0_0-hmac-32bit-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE CaaS Platform ALL (x86_64): libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - SUSE CaaS Platform 3.0 (x86_64): libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): libopenssl1_0_0-1.0.2j-60.52.1 libopenssl1_0_0-debuginfo-1.0.2j-60.52.1 openssl-1.0.2j-60.52.1 openssl-debuginfo-1.0.2j-60.52.1 openssl-debugsource-1.0.2j-60.52.1 References: https://bugzilla.suse.com/1131291 _______________________________________________ sle-security-updates mailing list
Important: php security update. Date: Tue, 12 Jul 2005 18:02:56 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 40 x86_64 now available Comments: To: scientific The following ERRATA for SL 40 x86_64 are now available from: Synopsis: Important: krb5 security update Advisory ID: RHSA-2005:567-02 Cross references: RHSA-2005:562 Obsoletes: RHSA-2005:330 CVE Names: CAN-2004-0175 CAN-2005-1174 CAN-2005-1175 CAN-2005-1689 krb5-devel-1.3.4-17.x86_64.rpm krb5-libs-1.3.4-17.i386.rpm krb5-libs-1.3.4-17.x86_64.rpm krb5-server-1.3.4-17.x86_64.rpm krb5-workstation-1.3.4-17.x86_64.rpm Synopsis: Important: php security update Advisory ID: RHSA-2005:564-01 CVE Names: CAN-2005-1751 CAN-2005-1921 php-4.3.9-3.7.x86_64.rpm php-devel-4.3.9-3.7.x86_64.rpm php-domxml-4.3.9-3.7.x86_64.rpm php-gd-4.3.9-3.7.x86_64.rpm php-imap-4.3.9-3.7.x86_64.rpm php-ldap-4.3.9-3.7.x86_64.rpm php-mbstring-4.3.9-3.7.x86_64.rpm php-mysql-4.3.9-3.7.x86_64.rpm php-ncurses-4.3.9-3.7.x86_64.rpm php-odbc-4.3.9-3.7.x86_64.rpm php-pear-4.3.9-3.7.x86_64.rpm php-pgsql-4.3.9-3.7.x86_64.rpm php-snmp-4.3.9-3.7.x86_64.rpm php-xmlrpc-4.3.9-3.7.x86_64.rpm -Connie Sieh . Crucial patches for php and krb5 have been released for Scientific Linux. Act swiftly to secure your system.. Scientific Linux Security Update, PHP Security Fix, KRB5 Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.