SUSE-CU-2022:3098-1: Security update of bci/nodejs

sle-updates at lists.suse.com sle-updates at lists.suse.com
Wed Nov 23 09:28:17 UTC 2022


SUSE Container Update Advisory: bci/nodejs
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2022:3098-1
Container Tags        : bci/node:16 , bci/node:16-11.36 , bci/node:latest , bci/nodejs:16 , bci/nodejs:16-11.36 , bci/nodejs:latest
Container Release     : 11.36
Severity              : important
Type                  : security
References            : 1198165 1205126 CVE-2022-42898 
-----------------------------------------------------------------

The container bci/nodejs was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:4135-1
Released:    Mon Nov 21 00:13:40 2022
Summary:     Recommended update for libeconf
Type:        recommended
Severity:    moderate
References:  1198165
This update for libeconf fixes the following issues:

- Update to version 0.4.6+git
  - econftool:
    Parsing error: Reporting file and line nr. --delimeters=spaces accepting all kind of spaces for delimiter.
  - libeconf:
    Parse files correctly on space characters (1198165)

- Update to version 0.4.5+git
  - econftool:
    New call 'syntax' for checking the configuration files only. Returns an error string with line number if error.
    New options '--comment' and '--delimeters'

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:4153-1
Released:    Mon Nov 21 14:34:09 2022
Summary:     Security update for krb5
Type:        security
Severity:    important
References:  1205126,CVE-2022-42898
This update for krb5 fixes the following issues:

- CVE-2022-42898: Fixed integer overflow in PAC parsing (bsc#1205126).


The following package changes have been done:

- libeconf0-0.4.6+git20220427.3016f4e-150400.3.3.1 updated
- krb5-1.19.2-150400.3.3.1 updated
- container:sles15-image-15.0.0-27.14.18 updated


More information about the sle-updates mailing list