[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2023:0871-1 -- SLES container-suseconnect

ID: oval:org.secpod.oval:def:89048544Date: (C)2023-04-11   (M)2024-05-09
Class: PATCHFamily: unix




This update of container-suseconnect fixes the following issue: * container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7. * CVE-2022-41723: Fixed quadratic complexity in HPACK decoding . * CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls . * CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart . * CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results . * CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows .

Platform:
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP1
Product:
container-suseconnect
Reference:
SUSE-SU-2023:0871-1
CVE-2022-41720
CVE-2022-41723
CVE-2022-41724
CVE-2022-41725
CVE-2023-24532
CVE    5
CVE-2023-24532
CVE-2022-41723
CVE-2022-41720
CVE-2022-41724
...
CPE    3
cpe:/o:suse:suse_linux_enterprise_server:15:sp1
cpe:/o:suse:suse_linux_enterprise_server:15:sp3
cpe:/o:suse:suse_linux_enterprise_server:15:sp2

© SecPod Technologies