SUSE-CU-2023:3096-1: Security update of suse/sles12sp5
sle-security-updates at lists.suse.com
sle-security-updates at lists.suse.com
Sun Sep 24 07:06:16 UTC 2023
SUSE Container Update Advisory: suse/sles12sp5
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:3096-1
Container Tags : suse/sles12sp5:6.5.513 , suse/sles12sp5:latest
Container Release : 6.5.513
Severity : important
Type : security
References : 1201978 1210411 1210412 1214052 1214768 1215026 CVE-2016-3709
CVE-2023-28484 CVE-2023-29469 CVE-2023-38039 CVE-2023-39615 CVE-2023-4039
-----------------------------------------------------------------
The container suse/sles12sp5 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3640-1
Released: Mon Sep 18 13:58:28 2023
Summary: Security update for gcc12
Type: security
Severity: important
References: 1214052,CVE-2023-4039
This update for gcc12 fixes the following issues:
- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3665-1
Released: Mon Sep 18 21:51:22 2023
Summary: Security update for libxml2
Type: security
Severity: important
References: 1201978,1210411,1210412,1214768,CVE-2016-3709,CVE-2023-28484,CVE-2023-29469,CVE-2023-39615
This update for libxml2 fixes the following issues:
- CVE-2023-29469: Fixed not deterministic hashing of empty dict strings (bsc#1210412).
- CVE-2023-28484: Fixed NULL dereference in xmlSchemaFixupComplexType (bsc#1210411).
- CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768).
- CVE-2016-3709: Fixed cross-site scripting vulnerability in libxml (bsc#1201978).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3692-1
Released: Tue Sep 19 22:05:52 2023
Summary: Security update for curl
Type: security
Severity: important
References: 1215026,CVE-2023-38039
This update for curl fixes the following issues:
- CVE-2023-38039: Fixed possible DoS when receiving too large HTTP header. (bsc#1215026)
The following package changes have been done:
- libcurl4-8.0.1-11.71.1 updated
- libgcc_s1-12.3.0+git1204-1.13.1 updated
- libstdc++6-12.3.0+git1204-1.13.1 updated
- libxml2-2-2.9.4-46.65.1 updated
More information about the sle-security-updates
mailing list