The container bci/dotnet-aspnet was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:88-1 Container Tags : bci/dotnet-aspnet:7.0 , bci/dotnet-aspnet:7.0-19.1 , bci/dotnet-aspnet:7.0.14 , bci/dotnet-aspnet:7.0.14-19.1 , bci/dotnet-aspnet:latest Container Release : 19.1 Severity : low Type : security References : 1217969 CVE-2023-39804 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:70-1 Released: Tue Jan 9 18:29:39 2024 Summary: Security update for tar Type: security Severity: low References: 1217969,CVE-2023-39804 This update for tar fixes the following issues: - CVE-2023-39804: Fixed extension attributes in PAX archives incorrect hanling (bsc#1217969). The following package changes have been done: - tar-1.34-150000.3.34.1 updated - container:sles15-image-15.0.0-36.5.71 updated . Check out the newly released safety notifications for bci/dotnet-aspnet as detailed in advisory ID SUSE-CU-2024:88-2, which tackle minor vulnerabilities.. bci/dotnet-aspnet security update, container patch, tar security fix. . Severity: Low. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0842 https://linux.oracle.com/errata/ELSA-2023-0842.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: tar-1.30-6.el8_7.1.x86_64.rpm aarch64: tar-1.30-6.el8_7.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//tar-1.30-6.el8_7.1.src.rpm Related CVEs: CVE-2022-48303 Description of changes: [1.30-6.1] - Fix CVE-2022-48303 - Resolves: CVE-2022-48303 _______________________________________________ El-errata mailing list
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for tar ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1237-1 Rating: moderate References: #1120610 #1130496 Cross-References: CVE-2018-20482 CVE-2019-9923 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for tar fixes the following issues: Security issues fixed: - CVE-2019-9923: Fixed a denial of service while parsing certain archives with malformed extended headers in pax_decode_header() (bsc#1130496). - CVE-2018-20482: Fixed a denial of service when the '--sparse' option mishandles file shrinkage during read access (bsc#1120610). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1237=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): tar-1.30-lp150.7.1 tar-debuginfo-1.30-lp150.7.1 tar-debugsource-1.30-lp150.7.1 tar-rmt-1.30-lp150.7.1 tar-rmt-debuginfo-1.30-lp150.7.1 tar-tests-1.30-lp150.7.1 tar-tests-debuginfo-1.30-lp150.7.1 - openSUSE Leap 15.0 (noarch): tar-backup-scripts-1.30-lp150.7.1 tar-doc-1.30-lp150.7.1 tar-lang-1.30-lp150.7.1 References: https://www.suse.com/security/cve/CVE-2018-20482.html https://www.suse.com/security/cve/CVE-2019-9923.html https://bugzilla.suse.com/1120610 https://bugzilla.suse.com/1130496 -- . openSUSE Security Update: Security update for tar__________________________________________________. update, security, fixes, vulnerabilities, opensuse. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.