Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3360-1

Опубликовано: 22 сент. 2024
Источник: suse-cvrf

Описание

Security update for container-suseconnect

This update for container-suseconnect rebuilds it against current go1.21.13.1.

Security issues fixed: CVE-2024-24789, CVE-2024-24790, CVE-2024-24791

Список пакетов

Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.3/bci-base:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.4/bci-base:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.5/sle15:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle-micro/5.1/toolbox:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle-micro/5.2/toolbox:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle-micro/5.3/toolbox:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle-micro/5.4/toolbox:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle-micro/5.5/toolbox:latest
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle15:15.2
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle15:15.5
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle15:15.6
container-suseconnect-2.5.0-150000.4.55.1
Container suse/sle15:15.7
container-suseconnect-2.5.0-150000.4.55.1
SUSE Enterprise Storage 7.1
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Module for Containers 15 SP5
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Module for Containers 15 SP6
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Server 15 SP2-LTSS
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Server 15 SP3-LTSS
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Server 15 SP4-LTSS
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
container-suseconnect-2.5.0-150000.4.55.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
container-suseconnect-2.5.0-150000.4.55.1

Описание

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.


Затронутые продукты
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.3/bci-base:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.4/bci-base:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.5/sle15:latest:container-suseconnect-2.5.0-150000.4.55.1

Ссылки

Описание

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.


Затронутые продукты
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.3/bci-base:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.4/bci-base:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.5/sle15:latest:container-suseconnect-2.5.0-150000.4.55.1

Ссылки

Описание

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail.


Затронутые продукты
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.3/bci-base:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.4/bci-base:latest:container-suseconnect-2.5.0-150000.4.55.1
Container suse/ltss/sle15.5/sle15:latest:container-suseconnect-2.5.0-150000.4.55.1

Ссылки
Уязвимость SUSE-SU-2024:3360-1