SUSE-CU-2023:4056-1: Security update of suse/sle15

meissner at meissner at
Sat Dec 9 08:03:02 UTC 2023

SUSE Container Update Advisory: suse/sle15
Container Advisory ID : SUSE-CU-2023:4056-1
Container Tags        : suse/sle15:15.1 , suse/sle15:
Container Release     : 6.2.852
Severity              : important
Type                  : security
References            : 1215889 1216410 1217215 1217573 CVE-2023-38546 CVE-2023-46218

The container suse/sle15 was updated. The following patches have been included in this update:

Advisory ID: SUSE-SU-2023:4650-1
Released:    Wed Dec  6 11:09:31 2023
Summary:     Security update for curl
Type:        security
Severity:    moderate
References:  1215889,1217573,CVE-2023-38546,CVE-2023-46218
This update for curl fixes the following issues:

- CVE-2023-38546: Fixed a cookie injection with none file (bsc#1215889).
- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).

Advisory ID: SUSE-SU-2023:4672-1
Released:    Wed Dec  6 14:37:37 2023
Summary:     Security update for suse-build-key
Type:        security
Severity:    important
References:  1216410,1217215
This update for suse-build-key fixes the following issues:

This update runs a import-suse-build-key script.

The previous libzypp-post-script based installation is replaced
with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777).
  - suse-build-key-import.service
  - suse-build-key-import.timer

It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys.
After successful import the timer is disabled.

To manually import them you can also run:

# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc
# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc

The following package changes have been done:

- libcurl4-7.60.0-150000.56.1 updated
- suse-build-key-12.0-150000.8.37.1 updated

More information about the sle-security-updates mailing list