. Debian LTS Advisory DLA-4569-1
Improper restrictions in CORBA deserialization. (CVE-2023-21830) Handshake DoS attack against DTLS connections. (CVE-2023-21835) Soundbank URL remote loading. (CVE-2023-21843) . MGASA-2023-0037 - Updated java/timezone packages fix security vulnerability Publication date: 07 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0037.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-21830, CVE-2023-21835, CVE-2023-21843 Improper restrictions in CORBA deserialization. (CVE-2023-21830) Handshake DoS attack against DTLS connections. (CVE-2023-21835) Soundbank URL remote loading. (CVE-2023-21843) References: - https://bugs.mageia.org/show_bug.cgi?id=31452 - https://access.redhat.com/errata/RHSA-2023:0203 - https://access.redhat.com/errata/RHSA-2023:0200 - https://www.oracle.com/security-alerts/cpujan2023.html#AppendixJAVA - https://www.cve.org/CVERecord?id=CVE-2023-21830 - https://www.cve.org/CVERecord?id=CVE-2023-21835 - https://www.cve.org/CVERecord?id=CVE-2023-21843 SRPMS: - 8/core/java-1.8.0-openjdk-1.8.0.362.b09-1.mga8 - 8/core/java-11-openjdk-11.0.18.0.10-1.mga8 - 8/core/timezone-2022g-1.mga8 . Mageia 2023-0038 releases updates for python/libraries fixing various vulnerabilities such as injection flaws and memory corruption.. Mageia Security Update, Java Timezone Packages, CORBA Vulnerability, DoS Attack Fix. . Severity: Critical. LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:3059-1 Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.71 , suse/sle15:15.3 , suse/sle15:15.3.17.20.71 Container Release : 17.20.71 Severity : important Type : security References : 1177460 1202324 1204179 1204649 1204968 1205156 CVE-2022-3821 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:4056-1 Released: Thu Nov 17 15:38:08 2022 Summary: Security update for systemd Type: security Severity: moderate References: 1204179,1204968,CVE-2022-3821 This update for systemd fixes the following issues: - CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968). - Import commit 56bee38fd0da18dad5fc5c5d12c02238a22b50e2 * 8a70235d8a core: Add trigger limit for path units * 93e544f3a0 core/mount: also add default before dependency for automount mount units * 5916a7748c logind: fix crash in logind on user-specified message string - Document udev naming scheme (bsc#1204179). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:4066-1 Released: Fri Nov 18 10:43:00 2022 Summary: Recommended update for timezone Type: recommended Severity: important References: 1177460,1202324,1204649,1205156 This update for timezone fixes the following issues: Update timezone version from 2022a to 2022f (bsc#1177460, bsc#1204649, bsc#1205156): - Mexico will no longer observe DST except near the US border - Chihuahua moves to year-round -06 on 2022-10-30 - Fiji no longer observes DST - In vanguard form, GMT is now a Zone and Etc/GMTa link - zic now supports links to links, and vanguard form uses this - Simplify four Ontario zones - Fix a Y2438 bug when reading TZif data - Enable 64-bit time_t on 32-bit glibc platforms - Omit large-file support when no longer needed - Jordan and Syria switch from +02/+03 with DST to year-round +03 - Palestine transitions are now Saturdays at 02:00 - Simplify three Ukraine zones into one - Improve tzselect on intercontinental Zones - Chile's DST is delayed by a week in September 2022 (bsc#1202324) - Iran no longer observes DST after 2022 - Rename Europe/Kiev to Europe/Kyiv - New `zic -R` command option - Vanguard form now uses %z The following package changes have been done: - libsystemd0-246.16-150300.7.54.1 updated - libudev1-246.16-150300.7.54.1 updated - timezone-2022f-150000.75.15.1 updated . Essential security enhancement for SUSE container suse/sle15 focusing on systemd and timezone updates, including corrections for buffer overflow vulnerabilities.. SUSE Container Update,Systemd Security,Timezone Update. . Severity: Important. LinuxSecurity.com Team
The container suse/pcp was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:3047-1 Container Tags : suse/pcp:5 , suse/pcp:5.2 , suse/pcp:5.2.2 , suse/pcp:5.2.2-11.74 , suse/pcp:latest Container Release : 11.74 Severity : important Type : security References : 1177460 1199944 1202324 1204649 1205156 CVE-2022-1664 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:4066-1 Released: Fri Nov 18 10:43:00 2022 Summary: Recommended update for timezone Type: recommended Severity: important References: 1177460,1202324,1204649,1205156 This update for timezone fixes the following issues: Update timezone version from 2022a to 2022f (bsc#1177460, bsc#1204649, bsc#1205156): - Mexico will no longer observe DST except near the US border - Chihuahua moves to year-round -06 on 2022-10-30 - Fiji no longer observes DST - In vanguard form, GMT is now a Zone and Etc/GMT a link - zic now supports links to links, and vanguard form uses this - Simplify four Ontario zones - Fix a Y2438 bug when reading TZif data - Enable 64-bit time_t on 32-bit glibc platforms - Omit large-file support when no longer needed - Jordan and Syria switch from +02/+03 with DST to year-round +03 - Palestine transitions are now Saturdays at 02:00 - Simplify three Ukraine zones into one - Improve tzselect on intercontinental Zones - Chile's DST is delayed by a week in September 2022 (bsc#1202324) - Iran no longer observes DST after 2022 - Rename Europe/Kiev to Europe/Kyiv - New `zic -R` command option - Vanguard form now uses %z ----------------------------------------------------------------- Advisory ID:SUSE-SU-2022:4081-1 Released: Fri Nov 18 15:40:46 2022 Summary: Security update for dpkg Type: security Severity: low References: 1199944,CVE-2022-1664 This update for dpkg fixes the following issues: - CVE-2022-1664: Fixed a directory traversal vulnerability in Dpkg::Source::Archive (bsc#1199944). The following package changes have been done: - timezone-2022f-150000.75.15.1 updated - update-alternatives-1.19.0.4-150000.4.4.1 updated - container:bci-bci-init-15.4-15.4-24.33 updated . Revision for the suse/pcp image, focusing on critical vulnerabilities and improving time zone capabilities.. SUSE Container Patch, suse/pcp Advisory, Important Container Update. . Severity: Important. LinuxSecurity.com Team
The container bci/dotnet-sdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:3039-1 Container Tags : bci/dotnet-sdk:3.1 , bci/dotnet-sdk:3.1-47.30 , bci/dotnet-sdk:3.1.30 , bci/dotnet-sdk:3.1.30-47.30 Container Release : 47.30 Severity : important Type : security References : 1177460 1202324 1204179 1204649 1204968 1205156 CVE-2022-3821 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3999-1 Released: Tue Nov 15 17:08:04 2022 Summary: Security update for systemd Type: security Severity: moderate References: 1204179,1204968,CVE-2022-3821 This update for systemd fixes the following issues: - CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968). - Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428 * 0469b9f2bc pstore: do not try to load all known pstore modules * ad05f54439 pstore: Run after modules are loaded * ccad817445 core: Add trigger limit for path units * 281d818fe3 core/mount: also add default before dependency for automount mount units * ffe5b4afa8 logind: fix crash in logind on user-specified message string - Document udev naming scheme (bsc#1204179) - Make 'sle15-sp3' net naming scheme still available for backward compatibility reason ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:4066-1 Released: Fri Nov 18 10:43:00 2022 Summary: Recommended update for timezone Type: recommended Severity: important References: 1177460,1202324,1204649,1205156 This update for timezone fixes the following issues: Update timezone version from 2022a to 2022f(bsc#1177460, bsc#1204649, bsc#1205156): - Mexico will no longer observe DST except near the US border - Chihuahua moves to year-round -06 on 2022-10-30 - Fiji no longer observes DST - In vanguard form, GMT is now a Zone and Etc/GMT a link - zic now supports links to links, and vanguard form uses this - Simplify four Ontario zones - Fix a Y2438 bug when reading TZif data - Enable 64-bit time_t on 32-bit glibc platforms - Omit large-file support when no longer needed - Jordan and Syria switch from +02/+03 with DST to year-round +03 - Palestine transitions are now Saturdays at 02:00 - Simplify three Ukraine zones into one - Improve tzselect on intercontinental Zones - Chile's DST is delayed by a week in September 2022 (bsc#1202324) - Iran no longer observes DST after 2022 - Rename Europe/Kiev to Europe/Kyiv - New `zic -R` command option - Vanguard form now uses %z The following package changes have been done: - libsystemd0-249.12-150400.8.13.1 updated - timezone-2022f-150000.75.15.1 updated - container:sles15-image-15.0.0-27.14.16 updated . Crucial software patch for bci/dotnet-sdk resolves several vulnerabilities, such as memory overflows and corrections for time zone discrepancies.. bci/dotnet-sdk update,SUSE security advisory,important security updates. . Severity: Important. LinuxSecurity.com Team
This update includes the changes in tzdata 2022d. Notable changes are: - - Palestine now switches back to standard time on October 29. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3134-1
This update includes the changes in tzdata 2021a for the Perl bindings. For the list of changes, see DLA-2542-1. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2543-1
This update includes the changes in tzdata 2021a. Notable changes are: - South Sudan changed from +03 to +02 on 2021-02-01. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2542-1
Get the latest Linux and open source security news straight to your inbox.