SUSE-CU-2023:1619-1: Security update of suse/sles12sp4

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Thu May 25 07:07:42 UTC 2023


SUSE Container Update Advisory: suse/sles12sp4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:1619-1
Container Tags        : suse/sles12sp4:26.605 , suse/sles12sp4:latest
Container Release     : 26.605
Severity              : important
Type                  : security
References            : 1203248 1203249 1206309 1207992 1208329 1209209 1209210 1209211
                        1209212 1209214 1211231 1211232 1211233 1211339 428822 CVE-2022-43552
                        CVE-2023-23916 CVE-2023-27533 CVE-2023-27534 CVE-2023-27535 CVE-2023-27536
                        CVE-2023-27538 CVE-2023-28320 CVE-2023-28321 CVE-2023-28322 
-----------------------------------------------------------------

The container suse/sles12sp4 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:2228-1
Released:    Wed May 17 09:59:14 2023
Summary:     Security update for curl
Type:        security
Severity:    important
References:  1206309,1207992,1209209,1209210,1209211,1209212,1209214,1211231,1211232,1211233,1211339,CVE-2022-43552,CVE-2023-23916,CVE-2023-27533,CVE-2023-27534,CVE-2023-27535,CVE-2023-27536,CVE-2023-27538,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322
This update for curl fixes the following issues:

- CVE-2023-28320: Fixed siglongjmp race condition (bsc#1211231).
- CVE-2023-28321: Fixed IDN wildcard matching (bsc#1211232).
- CVE-2023-28322: Fixed POST-after-PUT confusion (bsc#1211233).
- CVE-2023-27533: Fixed TELNET option IAC injection (bsc#1209209).
- CVE-2023-27534: Fixed SFTP path ~ resolving discrepancy (bsc#1209210).
- CVE-2023-27535: Fixed FTP too eager connection reuse (bsc#1209211).
- CVE-2023-27536: Fixed GSS delegation too eager connection reuse (bsc#1209212).
- CVE-2023-27538: Fixed SSH connection too eager reuse still (bsc#1209214).
- CVE-2022-43552: HTTP Proxy deny use-after-free (bsc#1206309).
- CVE-2023-23916: Fixed HTTP multi-header compression denial of service (bsc#1207992).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:2249-1
Released:    Thu May 18 17:07:31 2023
Summary:     Recommended update for libzypp, zypper
Type:        recommended
Severity:    moderate
References:  1203248,1203249,1208329,428822
This update for libzypp, zypper fixes the following issues:
    
- Removing a PTF without enabled repos should always fail (bsc#1203248)
- zypp.conf: Introduce 'download.connect_timeout' [60 sec.] (bsc#1208329)
- Add expert (allow-*) options to all installer commands (bsc#428822)

- Provide 'removeptf' command (bsc#1203249)
  A remove command which prefers replacing dependant packages to removing them as well.
  A PTF is typically removed as soon as the fix it provides is applied to the latest official update of the dependant
  packages. But you don't want the dependant packages to be removed together with the PTF, which is what the remove
  command would do. The removeptf command however will aim to replace the dependant packages by their official
  update versions.


The following package changes have been done:

- base-container-licenses-3.0-1.350 updated
- container-suseconnect-2.0.0-1.232 updated
- libcurl4-7.60.0-4.56.1 updated
- libzypp-16.22.7-48.2 updated
- zypper-1.13.64-21.55.2 updated


More information about the sle-security-updates mailing list