SUSE-CU-2021:219-1: Security update of suse/sles12sp4

sle-updates at lists.suse.com sle-updates at lists.suse.com
Fri May 28 06:12:42 UTC 2021


SUSE Container Update Advisory: suse/sles12sp4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2021:219-1
Container Tags        : suse/sles12sp4:26.298 , suse/sles12sp4:latest
Container Release     : 26.298
Severity              : moderate
Type                  : security
References            : 1175109 1177976 1179398 1179399 1179593 1183933 1186114 CVE-2020-8231
                        CVE-2020-8284 CVE-2020-8285 CVE-2020-8286 CVE-2021-22876 CVE-2021-22898
-----------------------------------------------------------------

The container suse/sles12sp4 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:1786-1
Released:    Thu May 27 16:45:41 2021
Summary:     Security update for curl
Type:        security
Severity:    moderate
References:  1175109,1177976,1179398,1179399,1179593,1183933,1186114,CVE-2020-8231,CVE-2020-8284,CVE-2020-8285,CVE-2020-8286,CVE-2021-22876,CVE-2021-22898
This update for curl fixes the following issues:
- CVE-2021-22898: TELNET stack contents disclosure (bsc#1186114)
- CVE-2021-22876: The automatic referer leaks credentials (bsc#1183933)
- CVE-2020-8286: Inferior OCSP verification (bsc#1179593)
- CVE-2020-8285: FTP wildcard stack overflow (bsc#1179399)
- CVE-2020-8284: Trusting FTP PASV responses (bsc#1179398)
- CVE-2020-8231: libcurl will pick and use the wrong connection with multiple requests with libcurl's multi API and the 'CURLOPT_CONNECT_ONLY' option (bsc#1175109)
- Fix: SFTP uploads result in empty uploaded files (bsc#1177976)



More information about the sle-updates mailing list