SUSE-CU-2023:3096-1: Security update of suse/sles12sp5

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Sun Sep 24 07:06:16 UTC 2023


SUSE Container Update Advisory: suse/sles12sp5
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:3096-1
Container Tags        : suse/sles12sp5:6.5.513 , suse/sles12sp5:latest
Container Release     : 6.5.513
Severity              : important
Type                  : security
References            : 1201978 1210411 1210412 1214052 1214768 1215026 CVE-2016-3709
                        CVE-2023-28484 CVE-2023-29469 CVE-2023-38039 CVE-2023-39615 CVE-2023-4039
-----------------------------------------------------------------

The container suse/sles12sp5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3640-1
Released:    Mon Sep 18 13:58:28 2023
Summary:     Security update for gcc12
Type:        security
Severity:    important
References:  1214052,CVE-2023-4039
This update for gcc12 fixes the following issues:

- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3665-1
Released:    Mon Sep 18 21:51:22 2023
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1201978,1210411,1210412,1214768,CVE-2016-3709,CVE-2023-28484,CVE-2023-29469,CVE-2023-39615
This update for libxml2 fixes the following issues:

- CVE-2023-29469: Fixed not deterministic hashing of empty dict strings (bsc#1210412).
- CVE-2023-28484: Fixed NULL dereference in xmlSchemaFixupComplexType (bsc#1210411).
- CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768).
- CVE-2016-3709: Fixed cross-site scripting vulnerability in libxml (bsc#1201978).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3692-1
Released:    Tue Sep 19 22:05:52 2023
Summary:     Security update for curl
Type:        security
Severity:    important
References:  1215026,CVE-2023-38039
This update for curl fixes the following issues:

- CVE-2023-38039: Fixed possible DoS when receiving too large HTTP header. (bsc#1215026)


The following package changes have been done:

- libcurl4-8.0.1-11.71.1 updated
- libgcc_s1-12.3.0+git1204-1.13.1 updated
- libstdc++6-12.3.0+git1204-1.13.1 updated
- libxml2-2-2.9.4-46.65.1 updated


More information about the sle-security-updates mailing list