The container bci/dotnet-aspnet was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4193-1 Container Tags : bci/dotnet-aspnet:7.0 , bci/dotnet-aspnet:7.0-18.25 , bci/dotnet-aspnet:7.0.14 , bci/dotnet-aspnet:7.0.14-18.25 , bci/dotnet-aspnet:latest Container Release : 18.25 Severity : moderate Type : security References : 1201384 1218014 CVE-2023-50495 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4891-1 Released: Mon Dec 18 16:31:49 2023 Summary: Security update for ncurses Type: security Severity: moderate References: 1201384,1218014,CVE-2023-50495 This update for ncurses fixes the following issues: - CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014) - Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384) The following package changes have been done: - libncurses6-6.1-150000.5.20.1 updated - terminfo-base-6.1-150000.5.20.1 updated - ncurses-utils-6.1-150000.5.20.1 updated - container:sles15-image-15.0.0-36.5.67 updated . The latest patch for the Red Hat container ubi8/dotnet-aspnet resolves concerns regarding a gcc memory access violation.. bci/dotnet-aspnet Update, Security Patch, Container Advisory, ncurses Fixes, Software Security Update. . LinuxSecurity.com Team
The container suse/389-ds was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/389-ds ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3021-1 Container Tags : suse/389-ds:2.2 , suse/389-ds:2.2-14.62 , suse/389-ds:latest Container Release : 14.62 Severity : important Type : security References : 1214052 1214768 CVE-2023-39615 CVE-2023-4039 ----------------------------------------------------------------- The container suse/389-ds was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3661-1 Released: Mon Sep 18 21:44:09 2023 Summary: Security update for gcc12 Type: security Severity: important References: 1214052,CVE-2023-4039 This update for gcc12 fixes the following issues: - CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3666-1 Released: Mon Sep 18 21:52:18 2023 Summary: Security update for libxml2 Type: security Severity: important References: 1214768,CVE-2023-39615 This update for libxml2 fixes the following issues: - CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768). The following package changes have been done: - libgcc_s1-12.3.0+git1204-150000.1.16.1 updated - libstdc++6-12.3.0+git1204-150000.1.16.1 updated - libxml2-2-2.10.3-150500.5.8.1 updated - container:sles15-image-15.0.0-36.5.34 updated . This release includes vital improvements for ubuntu/postgresql, tackling vulnerabilities in gcc12 and libcurl.. SUSE Container Security, suse/389-ds Update, Important Security Patches, SUSE CU 2023, Software Security Fixes. . Severity: Important. LinuxSecurity.com Team
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.1/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2541-1 Container Tags : suse/sle-micro/5.1/toolbox:12.1 , suse/sle-micro/5.1/toolbox:12.1-2.2.432 , suse/sle-micro/5.1/toolbox:latest Container Release : 2.2.432 Severity : moderate Type : security References : 1211079 1213514 CVE-2022-41409 ----------------------------------------------------------------- The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3210-1 Released: Mon Aug 7 15:20:04 2023 Summary: Security update for pcre2 Type: security Severity: moderate References: 1213514,CVE-2022-41409 This update for pcre2 fixes the following issues: - CVE-2022-41409: Fixed integer overflow vulnerability in pcre2test that allows attackers to cause a denial of service via negative input (bsc#1213514). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3218-1 Released: Mon Aug 7 16:52:13 2023 Summary: Recommended update for cryptsetup Type: recommended Severity: moderate References: 1211079 This update for cryptsetup fixes the following issues: - Handle system with low memory and no swap space (bsc#1211079) The following package changes have been done: - libcryptsetup12-hmac-2.3.7-150300.3.8.1 updated - libcryptsetup12-2.3.7-150300.3.8.1 updated - libpcre2-8-0-10.31-150000.3.15.1 updated . SUSE Software Maintenance Notification: suse/sle-micro/5.1/toolbox enhancements for pcre2 and cryptsetup resolving vulnerabilities and improving security measures.. SUSE Update, Toolbox Security Patch, Container Advisory. . LinuxSecurity.com Team
The container suse/pcp was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1890-1 Container Tags : suse/pcp:5 , suse/pcp:5-16.3 , suse/pcp:5.2 , suse/pcp:5.2-16.3 , suse/pcp:5.2.5 , suse/pcp:5.2.5-16.3 , suse/pcp:latest Container Release : 16.3 Severity : moderate Type : security References : 1211795 CVE-2023-2953 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2484-1 Released: Mon Jun 12 08:49:58 2023 Summary: Security update for openldap2 Type: security Severity: moderate References: 1211795,CVE-2023-2953 This update for openldap2 fixes the following issues: - CVE-2023-2953: Fixed null pointer deref in ber_memalloc_x (bsc#1211795). The following package changes have been done: - libldap-data-2.4.46-150200.14.14.1 updated - libldap-2_4-2-2.4.46-150200.14.14.1 updated - container:bci-bci-init-15.4-15.4-27.3 updated . A new security patch for SUSE Container advisory SUSE-CU-2023:1890-1 has been released, addressing vulnerabilities in suse/pcp and openldap2.. suse container advisory, suse pcp update, openldap security fix. . LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1373-1 Container Tags : suse/sle15:15.1 , suse/sle15:15.1.6.2.761 Container Release : 6.2.761 Severity : moderate Type : security References : 1209533 1210507 CVE-2022-4899 CVE-2023-29383 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2068-1 Released: Fri Apr 28 13:55:00 2023 Summary: Security update for shadow Type: security Severity: moderate References: 1210507,CVE-2023-29383 This update for shadow fixes the following issues: - CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2074-1 Released: Fri Apr 28 17:02:25 2023 Summary: Security update for zstd Type: security Severity: moderate References: 1209533,CVE-2022-4899 This update for zstd fixes the following issues: - CVE-2022-4899: Fixed buffer overrun in util.c (bsc#1209533). The following package changes have been done: - libzstd1-1.4.4-150000.1.9.1 updated - shadow-4.6-150100.3.8.1 updated . Routine security patches for the SUSE container suse/sle15 address vulnerabilities associated with shadow and zstd.. SUSE Container Update, Shadow Fix, Zstd Update. . LinuxSecurity.com Team
The container suse/389-ds was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/389-ds ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1310-1 Container Tags : suse/389-ds:2.0 , suse/389-ds:2.0-21.18 , suse/389-ds:latest Container Release : 21.18 Severity : moderate Type : security References : 1209918 1210411 1210412 CVE-2023-28484 CVE-2023-29469 ----------------------------------------------------------------- The container suse/389-ds was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2053-1 Released: Thu Apr 27 11:31:08 2023 Summary: Security update for libxml2 Type: security Severity: moderate References: 1209918,1210411,1210412,CVE-2023-28484,CVE-2023-29469 This update for libxml2 fixes the following issues: - CVE-2023-29469: Fixed inconsistent result when hashing empty strings (bsc#1210412). - CVE-2023-28484: Fixed NULL pointer dereference in xmlSchemaFixupComplexType (bsc#1210411). The following non-security bug was fixed: - Remove unneeded dependency (bsc#1209918). The following package changes have been done: - libxml2-2-2.9.14-150400.5.16.1 updated - container:sles15-image-15.0.0-27.14.55 updated . SUSE has released a security advisory on container security, highlighting moderate severity patches for the 389 Directory Server (389-ds) to boost security and compliance. suse container, 389-ds update, security patch, libxml2 fix, container security advisory. . LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1133-1 Container Tags : suse/sle15:15.2 , suse/sle15:15.2.9.5.284 Container Release : 9.5.284 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1851-1 Released: Fri Apr 14 15:08:38 2023 Summary: Security update for container-suseconnect Type: security Severity: important References: This update for container-suseconnect fixes the following issue: - rebuilt against current go version. The following package changes have been done: - container-suseconnect-2.4.0-150000.4.26.1 updated . Maintain safety with SUSE Container Upgrade for suse/sle15, featuring critical updates and repairs.. SUSE Container Update, suse/sle15, security patches, container advisory, system update. . Severity: Important. LinuxSecurity.com Team
The container suse/pcp was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:842-1 Container Tags : suse/pcp:5 , suse/pcp:5-13.18 , suse/pcp:5.2 , suse/pcp:5.2-13.18 , suse/pcp:5.2.5 , suse/pcp:5.2.5-13.18 , suse/pcp:latest Container Release : 13.18 Severity : moderate Type : security References : 1209209 1209210 1209211 1209212 1209214 CVE-2023-27533 CVE-2023-27534 CVE-2023-27535 CVE-2023-27536 CVE-2023-27538 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1582-1 Released: Mon Mar 27 10:31:52 2023 Summary: Security update for curl Type: security Severity: moderate References: 1209209,1209210,1209211,1209212,1209214,CVE-2023-27533,CVE-2023-27534,CVE-2023-27535,CVE-2023-27536,CVE-2023-27538 This update for curl fixes the following issues: - CVE-2023-27533: Fixed TELNET option IAC injection (bsc#1209209). - CVE-2023-27534: Fixed SFTP path ~ resolving discrepancy (bsc#1209210). - CVE-2023-27535: Fixed FTP too eager connection reuse (bsc#1209211). - CVE-2023-27536: Fixed GSS delegation too eager connection reuse (bsc#1209212). - CVE-2023-27538: Fixed SSH connection too eager reuse still (bsc#1209214). The following package changes have been done: - libcurl4-7.79.1-150400.5.18.1 updated - container:bci-bci-init-15.4-15.4-26.11 updated . The latest update for the SUSE container image suse/pcp addresses security vulnerabilities in curl, categorized with moderate severity.. SUSE Container, suse/pcp Security, curl Update, Patch Management, Container Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.