SUSE-CU-2021:219-1: Security update of suse/sles12sp4
sle-updates at lists.suse.com
sle-updates at lists.suse.com
Fri May 28 06:12:42 UTC 2021
SUSE Container Update Advisory: suse/sles12sp4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2021:219-1
Container Tags : suse/sles12sp4:26.298 , suse/sles12sp4:latest
Container Release : 26.298
Severity : moderate
Type : security
References : 1175109 1177976 1179398 1179399 1179593 1183933 1186114 CVE-2020-8231
CVE-2020-8284 CVE-2020-8285 CVE-2020-8286 CVE-2021-22876 CVE-2021-22898
-----------------------------------------------------------------
The container suse/sles12sp4 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:1786-1
Released: Thu May 27 16:45:41 2021
Summary: Security update for curl
Type: security
Severity: moderate
References: 1175109,1177976,1179398,1179399,1179593,1183933,1186114,CVE-2020-8231,CVE-2020-8284,CVE-2020-8285,CVE-2020-8286,CVE-2021-22876,CVE-2021-22898
This update for curl fixes the following issues:
- CVE-2021-22898: TELNET stack contents disclosure (bsc#1186114)
- CVE-2021-22876: The automatic referer leaks credentials (bsc#1183933)
- CVE-2020-8286: Inferior OCSP verification (bsc#1179593)
- CVE-2020-8285: FTP wildcard stack overflow (bsc#1179399)
- CVE-2020-8284: Trusting FTP PASV responses (bsc#1179398)
- CVE-2020-8231: libcurl will pick and use the wrong connection with multiple requests with libcurl's multi API and the 'CURLOPT_CONNECT_ONLY' option (bsc#1175109)
- Fix: SFTP uploads result in empty uploaded files (bsc#1177976)
More information about the sle-updates
mailing list