SUSE-CU-2023:2477-1: Security update of suse/sle15
sle-security-updates at lists.suse.com
sle-security-updates at lists.suse.com
Tue Aug 1 11:25:36 UTC 2023
SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:2477-1
Container Tags : suse/sle15:15.1 , suse/sle15:15.1.6.2.796
Container Release : 6.2.796
Severity : moderate
Type : security
References : 1193015 1211419 1213487 1213517 CVE-2023-2603 CVE-2023-3446
-----------------------------------------------------------------
The container suse/sle15 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:2955-1
Released: Tue Jul 25 05:22:54 2023
Summary: Recommended update for util-linux
Type: recommended
Severity: moderate
References: 1193015
This update for util-linux fixes the following issues:
- Fix memory leak on parse errors in libmount. (bsc#1193015)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:2956-1
Released: Tue Jul 25 08:33:38 2023
Summary: Security update for libcap
Type: security
Severity: moderate
References: 1211419,CVE-2023-2603
This update for libcap fixes the following issues:
- CVE-2023-2603: Fixed an integer overflow or wraparound in libcap/cap_alloc.c:_libcap_strdup() (bsc#1211419).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:2961-1
Released: Tue Jul 25 09:32:56 2023
Summary: Security update for openssl-1_1
Type: security
Severity: moderate
References: 1213487,CVE-2023-3446
This update for openssl-1_1 fixes the following issues:
- CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:3068-1
Released: Mon Jul 31 16:33:43 2023
Summary: Recommended update for openssl-1_1
Type: recommended
Severity: moderate
References: 1213517
This update for openssl-1_1 fixes the following issues:
- Dont pass zero length input to EVP_Cipher (bsc#1213517)
The following package changes have been done:
- libblkid1-2.33.2-150100.4.37.1 updated
- libcap2-2.26-150000.4.9.1 updated
- libfdisk1-2.33.2-150100.4.37.1 updated
- libmount1-2.33.2-150100.4.37.1 updated
- libopenssl1_1-1.1.0i-150100.14.62.1 updated
- libsmartcols1-2.33.2-150100.4.37.1 updated
- libuuid1-2.33.2-150100.4.37.1 updated
- openssl-1_1-1.1.0i-150100.14.62.1 updated
- util-linux-2.33.2-150100.4.37.1 updated
More information about the sle-security-updates
mailing list