* bsc#1237058 * bsc#1237062 Cross-References: * CVE-2025-24031 . # Security update for pam_pkcs11 Announcement ID: SUSE-SU-2025:0712-1 Release Date: 2025-02-25T10:38:13Z Rating: moderate References: * bsc#1237058 * bsc#1237062 Cross-References: * CVE-2025-24031 * CVE-2025-24032 CVSS scores: * CVE-2025-24031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-24031 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-24031 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-24032 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-24032 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2025-24032 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for pam_pkcs11 fixes the following issues: * CVE-2025-24032: default value for `cert_policy` (`none`) allows for authentication bypass (bsc#1237062). * CVE-2025-24031: uninitialized pointer dereference caused by user pressing ctrl-c/ctrl-d when asked for PIN leads to crash (bsc#1237058). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listedfor your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-712=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-712=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-712=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-712=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-712=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-712=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-712=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-712=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 * SUSE Linux Enterprise Micro 5.2 (aarch64s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.10-150100.3.6.1 * pam_pkcs11-debuginfo-0.6.10-150100.3.6.1 * pam_pkcs11-0.6.10-150100.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24031.html * https://www.suse.com/security/cve/CVE-2025-24032.html * https://bugzilla.suse.com/show_bug.cgi?id=1237058 * https://bugzilla.suse.com/show_bug.cgi?id=1237062 . SUSE released a security advisory for pam_pkcs11, fixing two vulnerabilities along with patch instructions.. SUSE Linux Micro,pam_pkcs11,security advisory,update instructions. . LinuxSecurity.com Team
An update that fixes 23 vulnerabilities is now available. An update that fixes 23 vulnerabilities is now available. An update that fixes 23 vulnerabilities is now available.. SUSE Security Update: Security update for flash-player ______________________________________________________________________________ Announcement ID: SUSE-SU-2015:1614-1 Rating: important References: #946880 Cross-References: CVE-2015-5567 CVE-2015-5568 CVE-2015-5570 CVE-2015-5571 CVE-2015-5572 CVE-2015-5573 CVE-2015-5574 CVE-2015-5575 CVE-2015-5576 CVE-2015-5577 CVE-2015-5578 CVE-2015-5579 CVE-2015-5580 CVE-2015-5581 CVE-2015-5582 CVE-2015-5584 CVE-2015-5587 CVE-2015-5588 CVE-2015-6676 CVE-2015-6677 CVE-2015-6678 CVE-2015-6679 CVE-2015-6682 Affected Products: SUSE Linux Enterprise Desktop 11-SP4 SUSE Linux Enterprise Desktop 11-SP3 ______________________________________________________________________________ An update that fixes 23 vulnerabilities is now available. Description: Adobe Flash Player was updated to 11.2.202.521 (APSB15-23 bsc#946880) fixing several security issues: More information can be found on: Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11-SP4: zypper in -t patch sledsp4-flash-player-12101=1 - SUSE Linux Enterprise Desktop 11-SP3: zypper in -t patch sledsp3-flash-player-12101=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11-SP4 (i586 x86_64): flash-player-11.2.202.521-0.17.1 flash-player-gnome-11.2.202.521-0.17.1 flash-player-kde4-11.2.202.521-0.17.1 - SUSE Linux Enterprise Desktop 11-SP3 (i586 x86_64): flash-player-11.2.202.521-0.17.1 flash-player-gnome-11.2.202.521-0.17.1 flash-player-kde4-11.2.202.521-0.17.1 References: https://www.suse.com/security/cve/CVE-2015-5567.html https://www.suse.com/security/cve/CVE-2015-5568.html https://www.suse.com/security/cve/CVE-2015-5570.html https://www.suse.com/security/cve/CVE-2015-5571.html https://www.suse.com/security/cve/CVE-2015-5572.html https://www.suse.com/security/cve/CVE-2015-5573.html https://www.suse.com/security/cve/CVE-2015-5574.html https://www.suse.com/security/cve/CVE-2015-5575.html https://www.suse.com/security/cve/CVE-2015-5576.html https://www.suse.com/security/cve/CVE-2015-5577.html https://www.suse.com/security/cve/CVE-2015-5578.html https://www.suse.com/security/cve/CVE-2015-5579.html https://www.suse.com/security/cve/CVE-2015-5580.html https://www.suse.com/security/cve/CVE-2015-5581.html https://www.suse.com/security/cve/CVE-2015-5582.html https://www.suse.com/security/cve/CVE-2015-5584.html https://www.suse.com/security/cve/CVE-2015-5587.html https://www.suse.com/security/cve/CVE-2015-5588.html https://www.suse.com/security/cve/CVE-2015-6676.html https://www.suse.com/security/cve/CVE-2015-6677.html https://www.suse.com/security/cve/CVE-2015-6678.html https://www.suse.com/security/cve/CVE-2015-6679.html https://www.suse.com/security/cve/CVE-2015-6682.html https://bugzilla.suse.com/946880 . SUSE Security Update for flash-player: addresses 23 vulnerabilities along with comprehensive installation guidance and information regarding the impacted products.. SUSE Linux Enterprise, Flash Player Security Fix, Software Update, Security Advisory, Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.