Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 7 articles for you...
100

SUSE: 2024:2625-1 Important: p7zip Buffer Overflow and Read Issues

* bsc#1227358 * bsc#1227359 Cross-References: * CVE-2023-52168 . # Security update for p7zip Announcement ID: SUSE-SU-2024:2625-1 Rating: important References: * bsc#1227358 * bsc#1227359 Cross-References: * CVE-2023-52168 * CVE-2023-52169 CVSS scores: * CVE-2023-52168 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-52169 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * Basesystem Module 15-SP5 * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Retail BranchServer 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for p7zip fixes the following issues: * CVE-2023-52168: Fixed heap-based buffer overflow in the NTFS handler allows two bytes to be overwritten at multiple offsets (bsc#1227358) * CVE-2023-52169: Fixed out-of-bounds read in NTFS handler (bsc#1227359) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2625=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2625=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-2625=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-2625=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-2625=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-2625=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-2625=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-2625=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-2625=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-2625=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-2625=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-2625=1 * SUSE Linux EnterpriseServer for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-2625=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-2625=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-2625=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-2625=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-2625=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-2625=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-2625=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * openSUSE Leap 15.5 (noarch) * p7zip-doc-16.02-150200.14.12.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * openSUSE Leap 15.6 (noarch) * p7zip-doc-16.02-150200.14.12.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 *p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Manager Proxy 4.3 (x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52168.html * https://www.suse.com/security/cve/CVE-2023-52169.html * https://bugzilla.suse.com/show_bug.cgi?id=1227358 * https://bugzilla.suse.com/show_bug.cgi?id=1227359 . Urgent update for p7zip addresses memory leaks and read vulnerabilities in SUSE software, enhancing system protection. Take action immediately!. p7zip security update, SUSE Linux vulnerabilities, enterprise storage patch, buffer overflow fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 30, 2024 Important SuSE
100

SUSE: 2024:0732-1 Important: Nodejs14 DoS and SSRF Fixes for Users

* bsc#1219993 * bsc#1219997 * bsc#1220014 * bsc#1220053 . # Security update for nodejs14 Announcement ID: SUSE-SU-2024:0732-1 Rating: important References: * bsc#1219993 * bsc#1219997 * bsc#1220014 * bsc#1220053 Cross-References: * CVE-2023-46809 * CVE-2024-22019 * CVE-2024-22025 * CVE-2024-24806 CVSS scores: * CVE-2023-46809 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2024-22019 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-24806 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-24806 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves four vulnerabilities can now be installed. ## Description: This update for nodejs14 fixes the following issues: Security issues fixed: * CVE-2023-46809: Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) (bsc#1219997). * CVE-2024-22019: http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (bsc#1219993). * CVE-2024-22025: Denial of Service by resource exhaustion in fetch() brotli decoding (bsc#1220014). * CVE-2024-24806: fix improper domain lookup that potentially leads to SSRF attacks (bsc#1219724). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methodslike YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-732=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-732=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-732=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-732=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-732=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * nodejs14-debuginfo-14.21.3-150200.15.55.1 * nodejs14-devel-14.21.3-150200.15.55.1 * nodejs14-14.21.3-150200.15.55.1 * nodejs14-debugsource-14.21.3-150200.15.55.1 * npm14-14.21.3-150200.15.55.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * nodejs14-docs-14.21.3-150200.15.55.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * nodejs14-debuginfo-14.21.3-150200.15.55.1 * nodejs14-devel-14.21.3-150200.15.55.1 * nodejs14-14.21.3-150200.15.55.1 * nodejs14-debugsource-14.21.3-150200.15.55.1 * npm14-14.21.3-150200.15.55.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * nodejs14-docs-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * nodejs14-debuginfo-14.21.3-150200.15.55.1 * nodejs14-devel-14.21.3-150200.15.55.1 *nodejs14-14.21.3-150200.15.55.1 * nodejs14-debugsource-14.21.3-150200.15.55.1 * npm14-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * nodejs14-docs-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * nodejs14-debuginfo-14.21.3-150200.15.55.1 * nodejs14-devel-14.21.3-150200.15.55.1 * nodejs14-14.21.3-150200.15.55.1 * nodejs14-debugsource-14.21.3-150200.15.55.1 * npm14-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * nodejs14-docs-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * nodejs14-debuginfo-14.21.3-150200.15.55.1 * nodejs14-devel-14.21.3-150200.15.55.1 * nodejs14-14.21.3-150200.15.55.1 * nodejs14-debugsource-14.21.3-150200.15.55.1 * npm14-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * nodejs14-docs-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * nodejs14-debuginfo-14.21.3-150200.15.55.1 * nodejs14-devel-14.21.3-150200.15.55.1 * nodejs14-14.21.3-150200.15.55.1 * nodejs14-debugsource-14.21.3-150200.15.55.1 * npm14-14.21.3-150200.15.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * nodejs14-docs-14.21.3-150200.15.55.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * nodejs14-debuginfo-14.21.3-150200.15.55.1 * nodejs14-devel-14.21.3-150200.15.55.1 * nodejs14-14.21.3-150200.15.55.1 * nodejs14-debugsource-14.21.3-150200.15.55.1 * npm14-14.21.3-150200.15.55.1 * SUSE Enterprise Storage 7.1 (noarch) * nodejs14-docs-14.21.3-150200.15.55.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46809.html * https://www.suse.com/security/cve/CVE-2024-22019.html * https://www.suse.com/security/cve/CVE-2024-22025.html * https://www.suse.com/security/cve/CVE-2024-24806.html *https://bugzilla.suse.com/show_bug.cgi?id=1219993 * https://bugzilla.suse.com/show_bug.cgi?id=1219997 * https://bugzilla.suse.com/show_bug.cgi?id=1220014 * https://bugzilla.suse.com/show_bug.cgi?id=1220053 . Tackling key challenges in nodejs14 on SUSE; features essential updates and remediation techniques for users.. Nodejs14 Update, SUSE Security Advisory, DoS Attack Fix, SSRF Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 29, 2024 Important SuSE
100

SUSE: 2022:3429-1 Critical: DPDK Vulnerability and Overrun Exploit

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for dpdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3429-1 Rating: important References: #1202903 #1202956 Cross-References: CVE-2022-2132 CVE-2022-28199 CVSS scores: CVE-2022-2132 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H CVE-2022-2132 (SUSE): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H CVE-2022-28199 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2022-28199 (SUSE): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Manager Proxy 4.1 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dpdk fixes the following issues: - CVE-2022-2132: Fixed DoS when a vhost header crosses more than two descriptors and exhausts all mbufs (bsc#1202903). - CVE-2022-28199: Fixed buffer overflow in the vhost code (bsc#1202956). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-3429=1 - SUSEManager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-3429=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-3429=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-3429=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-3429=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-3429=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-3429=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-3429=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-3429=1 Package List: - SUSE Manager Server 4.1 (ppc64le x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Manager Proxy 4.1 (x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64): dpdk-thunderx-19.11.4-150200.3.20.1 dpdk-thunderx-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-debugsource-19.11.4-150200.3.20.1 dpdk-thunderx-devel-19.11.4-150200.3.20.1 dpdk-thunderx-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64): dpdk-thunderx-19.11.4-150200.3.20.1 dpdk-thunderx-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-debugsource-19.11.4-150200.3.20.1 dpdk-thunderx-devel-19.11.4-150200.3.20.1 dpdk-thunderx-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64): dpdk-thunderx-19.11.4-150200.3.20.1 dpdk-thunderx-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-debugsource-19.11.4-150200.3.20.1 dpdk-thunderx-devel-19.11.4-150200.3.20.1 dpdk-thunderx-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): dpdk-19.11.4-150200.3.20.1 dpdk-debuginfo-19.11.4-150200.3.20.1 dpdk-debugsource-19.11.4-150200.3.20.1 dpdk-devel-19.11.4-150200.3.20.1 dpdk-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-tools-19.11.4-150200.3.20.1 dpdk-tools-debuginfo-19.11.4-150200.3.20.1 libdpdk-20_0-19.11.4-150200.3.20.1 libdpdk-20_0-debuginfo-19.11.4-150200.3.20.1 - SUSE Enterprise Storage 7 (aarch64): dpdk-thunderx-19.11.4-150200.3.20.1 dpdk-thunderx-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-debugsource-19.11.4-150200.3.20.1 dpdk-thunderx-devel-19.11.4-150200.3.20.1 dpdk-thunderx-devel-debuginfo-19.11.4-150200.3.20.1 dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150200.24.126-150200.3.20.1 References: https://www.suse.com/security/cve/CVE-2022-2132.html https://www.suse.com/security/cve/CVE-2022-28199.html https://bugzilla.suse.com/1202903 https://bugzilla.suse.com/1202956 . Red Hat Security Alert: Significant update for libvirt addresses severe memory corruption and denial of service vulnerabilities with corresponding fixes.. SUSE Security Update, DPDK, Important Patch, Buffer Overflow, Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 27, 2022 Important SuSE
100

SUSE: 2022:2986-2 Critical: Open-VM-Tools Security Update

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for open-vm-tools ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2985-1 Rating: important References: #1202657 Cross-References: CVE-2022-31676 CVSS scores: CVE-2022-31676 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-31676 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Manager Proxy 4.1 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for open-vm-tools fixes the following issues: - CVE-2022-31676: Fixed an issue that could allow unprivileged users inside a virtual machine to escalate privileges (bsc#1202657). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-2985=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-2985=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-2985=1 - SUSE LinuxEnterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-2985=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-2985=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-2985=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-2985=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-2985=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-2985=1 Package List: - SUSE Manager Server 4.1 (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Manager Proxy 4.1 (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 - SUSE Enterprise Storage 7 (x86_64): libvmtools-devel-11.3.5-150200.5.16.11.1 libvmtools0-11.3.5-150200.5.16.11.1 libvmtools0-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-11.3.5-150200.5.16.11.1 open-vm-tools-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-debugsource-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-11.3.5-150200.5.16.11.1 open-vm-tools-desktop-debuginfo-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-11.3.5-150200.5.16.11.1 open-vm-tools-sdmp-debuginfo-11.3.5-150200.5.16.11.1 References: https://www.suse.com/security/cve/CVE-2022-31676.html https://bugzilla.suse.com/1202657 . An important security patch for open-vm-tools has been issued, rectifying an issue found in multiple SUSE variants.. open-vm-toolsupdate, privilege escalation fix, SUSE Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 01, 2022 Critical SuSE
100

SUSE: 2022:2179-1 Moderate: OpenSSL Shell Injection Threat

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2179-1 Rating: moderate References: #1200550 Cross-References: CVE-2022-2068 CVSS scores: CVE-2022-2068 (SUSE): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server for SAP 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl fixes the following issues: - CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-2179=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-2179=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-2179=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-2179=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patchSUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-2179=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-2179=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Enterprise Storage 6 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE CaaS Platform 4.0 (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 References: https://www.suse.com/security/cve/CVE-2022-2068.html https://bugzilla.suse.com/1200550 . SUSE has released a Security Update targeting the OpenSSL flaw CVE-2022-2068, classified with a moderate severity level, applicable to multiple SUSE offerings.. SUSE OpenSSL Update, SUSE Security Advisory, Linux Security Update. . LinuxSecurity.com Team

Calendar%202 Jun 24, 2022 SuSE
100

SUSE: 2022:2139-1 Important: Golang Alertmanager DoS Issue Fixed

An update that solves one vulnerability, contains one feature and has one errata is now available. . SUSE Security Update: Security update for golang-github-prometheus-alertmanager ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2139-1 Rating: important References: #1181400 #1196338 SLE-24077 Cross-References: CVE-2022-21698 CVSS scores: CVE-2022-21698 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-21698 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Enterprise Storage 6 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Tools 15 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability, contains one feature and has one errata is now available. Description: This update for golang-github-prometheus-alertmanager fixes the following issues: Update golang-github-prometheus-alertmanager from version 0.21.0 to version 0.23.0 (bsc#1196338, jsc#SLE-24077) - CVE-2022-21698: Denial of service using InstrumentHandlerCounter - Update vendor tarball with prometheus/client_golang 1.11.1 - Update required Go version to 1.16 - Use %autosetup macro - Update to version 0.23.0: * Release 0.23.0 * Release 0.23.0-rc.0 * amtool: Detect version drift and warn users (#2672) * Add ability to skip TLS verification for amtool (#2663) * Fix empty isEqual in amtool. (#2668) * Fix main tests (#2670) * cli: add new template render command (#2538) * OpsGenie: refer to alert instead of incident (#2609) * Docs: target_match and source_match are DEPRECATED (#2665) * Fix test not waiting for cluster member to be ready - Add go_modules to _service. - Added hardening to systemd service(s) with a modified prometheus-alertmanager.service (bsc#1181400) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2139=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2139=1 - SUSE Manager Tools 15: zypper in -t patch SUSE-SLE-Manager-Tools-15-2022-2139=1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2022-2139=1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.2-2022-2139=1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.1-2022-2139=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-2139=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-alertmanager-0.23.0-150100.4.7.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-alertmanager-0.23.0-150100.4.7.1 - SUSE Manager Tools 15 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-alertmanager-0.23.0-150100.4.7.1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-alertmanager-0.23.0-150100.4.7.1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-alertmanager-0.23.0-150100.4.7.1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-alertmanager-0.23.0-150100.4.7.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): golang-github-prometheus-alertmanager-0.23.0-150100.4.7.1 References: https://www.suse.com/security/cve/CVE-2022-21698.html https://bugzilla.suse.com/1181400 https://bugzilla.suse.com/1196338 . The latest security patch for golang-github-prometheus-alertmanager tackles critical vulnerabilities and improves overall capabilities of the application.. SUSE Update, Denial Of Service, Golang Fix, Alertmanager Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 20, 2022 Important SuSE
100

SUSE: 2022:1670-1 Critical: SQL Injection Vulnerability in OpenLDAP2

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openldap2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1670-1 Rating: important References: #1199240 Cross-References: CVE-2022-29155 CVSS scores: CVE-2022-29155 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-29155 (SUSE): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Micro 5.2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP4 SUSE Linux Enterprise Module for Legacy Software 15-SP3 SUSE Linux Enterprise Server SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications SUSE Linux Enterprise Server for SAPApplications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openldap2 fixes the following issues: - CVE-2022-29155: Fixed SQL injection in back-sql (bsc#1199240). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1670=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1670=1 - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-1670=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-1670=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-1670=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-1670=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-1670=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-1670=1 - SUSE Linux Enterprise Module for Legacy Software 15-SP3: zypper in -t patch SUSE-SLE-Module-Legacy-15-SP3-2022-1670=1 - SUSE Linux Enterprise Module for Development Tools 15-SP4: zypper in -t patchSUSE-SLE-Module-Development-Tools-15-SP4-2022-1670=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2022-1670=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-1670=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-1670=1 - SUSE Linux Enterprise Micro 5.2: zypper in -t patch SUSE-SUSE-MicroOS-5.2-2022-1670=1 - SUSE Linux Enterprise Micro 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-1670=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-1670=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-1670=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-1670=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-back-sock-2.4.46-150200.14.8.1 openldap2-back-sock-debuginfo-2.4.46-150200.14.8.1 openldap2-back-sql-2.4.46-150200.14.8.1 openldap2-back-sql-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - openSUSE Leap 15.4 (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - openSUSE Leap 15.4 (noarch): libldap-data-2.4.46-150200.14.8.1 openldap2-doc-2.4.46-150200.14.8.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-back-sock-2.4.46-150200.14.8.1 openldap2-back-sock-debuginfo-2.4.46-150200.14.8.1 openldap2-back-sql-2.4.46-150200.14.8.1 openldap2-back-sql-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - openSUSE Leap 15.3 (noarch): libldap-data-2.4.46-150200.14.8.1 openldap2-doc-2.4.46-150200.14.8.1 - openSUSE Leap 15.3 (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Manager Server 4.1 (ppc64le s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - SUSE Manager Server 4.1 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Manager Server 4.1 (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - SUSE Manager Retail Branch Server 4.1 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Manager Proxy 4.1 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Manager Proxy 4.1 (x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Server 15-SP2-BCL (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Module for Legacy Software 15-SP3 (aarch64 ppc64le s390x x86_64): openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - SUSE Linux Enterprise Module for Development Tools 15-SP4 (x86_64): openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (x86_64): openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 -SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Micro 5.2 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 - SUSE Linux Enterprise Micro 5.1 (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (noarch): libldap-data-2.4.46-150200.14.8.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): libldap-2_4-2-2.4.46-150200.14.8.1 libldap-2_4-2-debuginfo-2.4.46-150200.14.8.1 openldap2-2.4.46-150200.14.8.1 openldap2-back-meta-2.4.46-150200.14.8.1 openldap2-back-meta-debuginfo-2.4.46-150200.14.8.1 openldap2-back-perl-2.4.46-150200.14.8.1 openldap2-back-perl-debuginfo-2.4.46-150200.14.8.1 openldap2-client-2.4.46-150200.14.8.1 openldap2-client-debuginfo-2.4.46-150200.14.8.1 openldap2-contrib-2.4.46-150200.14.8.1 openldap2-contrib-debuginfo-2.4.46-150200.14.8.1 openldap2-debuginfo-2.4.46-150200.14.8.1 openldap2-debugsource-2.4.46-150200.14.8.1 openldap2-devel-2.4.46-150200.14.8.1 openldap2-devel-static-2.4.46-150200.14.8.1 openldap2-ppolicy-check-password-1.2-150200.14.8.1 openldap2-ppolicy-check-password-debuginfo-1.2-150200.14.8.1 - SUSE Enterprise Storage 7 (x86_64): libldap-2_4-2-32bit-2.4.46-150200.14.8.1 libldap-2_4-2-32bit-debuginfo-2.4.46-150200.14.8.1 openldap2-devel-32bit-2.4.46-150200.14.8.1 - SUSE Enterprise Storage 7(noarch): libldap-data-2.4.46-150200.14.8.1 References: https://www.suse.com/security/cve/CVE-2022-29155.html https://bugzilla.suse.com/1199240 . New release for openldap2 issued to address critical SQL injection flaw, rated high severity. Detailed guidance for installation provided.. SUSE Update, OpenLDAP Security, SQL Injection Fix, Patch Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 16, 2022 Important SuSE
100

SUSE: 2022:1462-1 Important: nodejs14 Denial of Service Threat

An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for nodejs14 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1462-1 Rating: important References: #1194819 #1196877 #1197283 #1198247 Cross-References: CVE-2021-44906 CVE-2021-44907 CVE-2022-0235 CVE-2022-0778 CVSS scores: CVE-2021-44906 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-44906 (SUSE): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2021-44907 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-44907 (SUSE): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVE-2022-0235 (SUSE): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N CVE-2022-0778 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-0778 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Web Scripting 15-SP3 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for nodejs14 fixes the following issues: - CVE-2022-0778: Fixed a infinite loop in BN_mod_sqrt() reachable when parsing certificates (bsc#1196877). - CVE-2021-44906: Fixed a prototype pollution in node-minimist (bsc#1198247). - CVE-2021-44907: Fixed a potential Denial of Service vulnerability in node-qs (bsc#1197283). - CVE-2022-0235: Fixed an exposure of sensitive information to an unauthorized actor in node-fetch (bsc#1194819). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1462=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1462=1 - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-1462=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-1462=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-1462=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-1462=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-1462=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-1462=1 - SUSE Linux Enterprise Module for Web Scripting 15-SP3: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP3-2022-1462=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patchSUSE-SLE-Product-HPC-15-SP2-LTSS-2022-1462=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-1462=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-1462=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): corepack14-14.19.1-150200.15.31.1 nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - openSUSE Leap 15.4 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - openSUSE Leap 15.3 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Manager Server 4.1 (ppc64le s390x x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Manager Server 4.1 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Manager Retail Branch Server 4.1 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Manager Proxy 4.1 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Manager Proxy 4.1 (x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Server 15-SP2-BCL (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP3 (aarch64 ppc64le s390x x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP3 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (noarch): nodejs14-docs-14.19.1-150200.15.31.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): nodejs14-14.19.1-150200.15.31.1 nodejs14-debuginfo-14.19.1-150200.15.31.1 nodejs14-debugsource-14.19.1-150200.15.31.1 nodejs14-devel-14.19.1-150200.15.31.1 npm14-14.19.1-150200.15.31.1 - SUSE Enterprise Storage 7 (noarch): nodejs14-docs-14.19.1-150200.15.31.1 References: https://www.suse.com/security/cve/CVE-2021-44906.html https://www.suse.com/security/cve/CVE-2021-44907.html https://www.suse.com/security/cve/CVE-2022-0235.html https://www.suse.com/security/cve/CVE-2022-0778.html https://bugzilla.suse.com/1194819 https://bugzilla.suse.com/1196877 https://bugzilla.suse.com/1197283 https://bugzilla.suse.com/1198247 . This update from SUSE resolves urgent vulnerabilities in nodejs14, tackling risks of Denial of Service and exposure of sensitive information. Make sure to update immediately!. SUSE Security Update,nodejs14 advisory,security risks,patch management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 28, 2022 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200