* bsc#1216378 Cross-References: * CVE-2023-45853 . # Security update for zlib Announcement ID: SUSE-SU-2023:4216-1 Rating: moderate References: * bsc#1216378 Cross-References: * CVE-2023-45853 CVSS scores: * CVE-2023-45853 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2023-45853 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for zlib fixes the following issues: * CVE-2023-45853: Fixed an integer overflow that would lead to a buffer overflow in the minizip subcomponent (bsc#1216378). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2023-4216=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4216=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4216=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4216=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * zlib-devel-static-1.2.11-11.37.1 * zlib-debugsource-1.2.11-11.37.1 * zlib-devel-1.2.11-11.37.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (s390x x86_64) * zlib-devel-32bit-1.2.11-11.37.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * zlib-devel-1.2.11-11.37.1 * libz1-1.2.11-11.37.1 *libz1-debuginfo-1.2.11-11.37.1 * zlib-debugsource-1.2.11-11.37.1 * zlib-devel-static-1.2.11-11.37.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libz1-debuginfo-32bit-1.2.11-11.37.1 * libz1-32bit-1.2.11-11.37.1 * zlib-devel-32bit-1.2.11-11.37.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * zlib-devel-1.2.11-11.37.1 * libz1-1.2.11-11.37.1 * libz1-debuginfo-1.2.11-11.37.1 * zlib-debugsource-1.2.11-11.37.1 * zlib-devel-static-1.2.11-11.37.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * zlib-devel-32bit-1.2.11-11.37.1 * libz1-32bit-1.2.11-11.37.1 * libz1-debuginfo-32bit-1.2.11-11.37.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * zlib-devel-1.2.11-11.37.1 * libz1-1.2.11-11.37.1 * libz1-debuginfo-1.2.11-11.37.1 * zlib-debugsource-1.2.11-11.37.1 * zlib-devel-static-1.2.11-11.37.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libz1-debuginfo-32bit-1.2.11-11.37.1 * libz1-32bit-1.2.11-11.37.1 * zlib-devel-32bit-1.2.11-11.37.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45853.html * https://bugzilla.suse.com/show_bug.cgi?id=1216378 . SUSE reveals a significant security fix for zlib, tackling an integer overflow issue that could pose security risks.. SUSE Security Update, zlib Patch, Buffer Overflow Issue, Software Vulnerability, SUSE Linux Updates. . LinuxSecurity.com Team
An update for zlib is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: zlib security update Advisory ID: RHSA-2023:0976-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0976 Issue date: 2023-02-28 CVE Names: CVE-2018-25032 ==================================================================== 1. Summary: An update for zlib is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.4) - x86_64 3. Description: The zlib packages provide a general-purpose lossless data compression library that is used by many different programs. Security Fix(es): * zlib: A flaw found in zlib when compressing (not decompressing) certain inputs (CVE-2018-25032) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2067945 - CVE-2018-25032 zlib: A flaw found in zlib when compressing (not decompressing) certain inputs 6. PackageList: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: zlib-1.2.7-17.el7_4.1.src.rpm x86_64: zlib-1.2.7-17.el7_4.1.i686.rpm zlib-1.2.7-17.el7_4.1.x86_64.rpm zlib-debuginfo-1.2.7-17.el7_4.1.i686.rpm zlib-debuginfo-1.2.7-17.el7_4.1.x86_64.rpm zlib-devel-1.2.7-17.el7_4.1.i686.rpm zlib-devel-1.2.7-17.el7_4.1.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.4): x86_64: minizip-1.2.7-17.el7_4.1.i686.rpm minizip-1.2.7-17.el7_4.1.x86_64.rpm minizip-devel-1.2.7-17.el7_4.1.i686.rpm minizip-devel-1.2.7-17.el7_4.1.x86_64.rpm zlib-debuginfo-1.2.7-17.el7_4.1.i686.rpm zlib-debuginfo-1.2.7-17.el7_4.1.x86_64.rpm zlib-static-1.2.7-17.el7_4.1.i686.rpm zlib-static-1.2.7-17.el7_4.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-25032 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY/3zotzjgjWX9erEAQjRCQ//Ro0HU1Tt7+Zblkm9OhYQt5qowtn36cJu t1pvHB3bMLnM4mkwg4QU+uUkhJGmjxBW0Fm/cQB2wttphDZZXIDT0YRVIy7HHgLz o535bEfBOFo11eKu8Zr3cHbfUIdWVkz1I4g8gCA09LKHDBPquFg9oMpAjgzhMcH5 +uLaTJnQaXwmMySC2XMwEZa6Pl6StJ+kFFwNmFe6XMYJuyGfnOnNUmpkiokYnTas 8KgeCMvJu0hhcMUtC9KK+P/ydyHjrMNqZHZIJsiFTTKpgli5BO6L6t9tP31O/AqF Bk1W/rChpct9+Nb0su92Ztbll/nRqazeajSqF1OEHyzqCROPFfldomibBCBCTfLS Fhwv/AHZ6Mw4DdJu1dHGeMWwS67Xz5RaFdUt55mXy1uIy9rljnGr4nkFx/3Gz0b0 Pl5VeTvL/+4+pqpZJVwo2dKZpV6Lv6IxrxWhH6IPNsNbmtpZ5bAY0BuO+UsYbN6Z sS5ts4uTLGF3ENvSmBRLDNdDD987TbiWvOTZNEzOAGXqTlYACU4n6I0ywLNZppGu g3+sFRKCNgFGafpn0uj+g0E2jV8/j36w57g5rbAQfWfWHQK3PzQOwumZX7sR1AzC 7XccLWXMoQnyPji/jtasKorlr73G//Eiewo0ACSdA0uOLJy/klGSTZ+l9BHGR7DN /oxXY+Wjkl0=fsnn -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Security fix for CVE-2018-25032. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-413a80a102 2022-04-18 17:14:34.868539 --------------------------------------------------------------------------------Name : rsync Product : Fedora 35 Version : 3.2.3 Release : 9.fc35 URL : / Summary : A program for synchronizing files over a network Description : Rsync uses a reliable algorithm to bring remote and host files into sync very quickly. Rsync is fast because it just sends the differences in the files over the network instead of sending the complete files. Rsync is often used as a very powerful mirroring process or just as a more capable replacement for the rcp command. A technical report which describes the rsync algorithm is included in this package. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-25032 --------------------------------------------------------------------------------ChangeLog: * Thu Apr 14 2022 Michal Ruprich - 3.2.3-9 - Fix for CVE-2018-25032 --------------------------------------------------------------------------------References: [ 1 ] Bug #2067945 - CVE-2018-25032 zlib: A flaw found in zlib v1.2.2.2 through zlib v1.2.11 when compressing (not decompressing!) certain inputs. https://bugzilla.redhat.com/show_bug.cgi?id=2067945 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-413a80a102' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.