SUSE-CU-2023:2477-1: Security update of suse/sle15

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Tue Aug 1 11:25:36 UTC 2023


SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:2477-1
Container Tags        : suse/sle15:15.1 , suse/sle15:15.1.6.2.796
Container Release     : 6.2.796
Severity              : moderate
Type                  : security
References            : 1193015 1211419 1213487 1213517 CVE-2023-2603 CVE-2023-3446 
-----------------------------------------------------------------

The container suse/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:2955-1
Released:    Tue Jul 25 05:22:54 2023
Summary:     Recommended update for util-linux
Type:        recommended
Severity:    moderate
References:  1193015
This update for util-linux fixes the following issues:

- Fix memory leak on parse errors in libmount. (bsc#1193015)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:2956-1
Released:    Tue Jul 25 08:33:38 2023
Summary:     Security update for libcap
Type:        security
Severity:    moderate
References:  1211419,CVE-2023-2603
This update for libcap fixes the following issues:

- CVE-2023-2603: Fixed an integer overflow or wraparound in libcap/cap_alloc.c:_libcap_strdup() (bsc#1211419).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:2961-1
Released:    Tue Jul 25 09:32:56 2023
Summary:     Security update for openssl-1_1
Type:        security
Severity:    moderate
References:  1213487,CVE-2023-3446
This update for openssl-1_1 fixes the following issues:

- CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:3068-1
Released:    Mon Jul 31 16:33:43 2023
Summary:     Recommended update for openssl-1_1
Type:        recommended
Severity:    moderate
References:  1213517
This update for openssl-1_1 fixes the following issues:

- Dont pass zero length input to EVP_Cipher (bsc#1213517)


The following package changes have been done:

- libblkid1-2.33.2-150100.4.37.1 updated
- libcap2-2.26-150000.4.9.1 updated
- libfdisk1-2.33.2-150100.4.37.1 updated
- libmount1-2.33.2-150100.4.37.1 updated
- libopenssl1_1-1.1.0i-150100.14.62.1 updated
- libsmartcols1-2.33.2-150100.4.37.1 updated
- libuuid1-2.33.2-150100.4.37.1 updated
- openssl-1_1-1.1.0i-150100.14.62.1 updated
- util-linux-2.33.2-150100.4.37.1 updated


More information about the sle-security-updates mailing list