Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3428-1

Опубликовано: 24 сент. 2024
Источник: suse-cvrf

Описание

Security update for apr

This update for apr fixes the following issues:

  • CVE-2023-49582: Fixed an unexpected lax shared memory permissions. (bsc#1229783)

Список пакетов

Container bci/php-apache:latest
libapr1-1.6.3-150000.3.6.1
Container containers/apache-tomcat:10.1-openjdk11
libapr1-1.6.3-150000.3.6.1
Container containers/apache-tomcat:10.1-openjdk17
libapr1-1.6.3-150000.3.6.1
Container containers/apache-tomcat:10.1-openjdk21
libapr1-1.6.3-150000.3.6.1
Container suse/manager/4.3/proxy-httpd:latest
libapr1-1.6.3-150000.3.6.1
Container suse/manager/5.0/x86_64/proxy-httpd:latest
libapr1-1.6.3-150000.3.6.1
Container suse/manager/5.0/x86_64/server:latest
libapr1-1.6.3-150000.3.6.1
Container suse/registry:latest
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP3-SAPCAL-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP3-SAPCAL-EC2-HVM
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP3-SAPCAL-GCE
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAP
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAP-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAP-EC2
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAP-GCE
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAPCAL
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAPCAL-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAPCAL-EC2
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP4-SAPCAL-GCE
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP5-SAPCAL-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP5-SAPCAL-EC2
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP5-SAPCAL-GCE
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAP
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAP-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAP-EC2
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAP-GCE
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAPCAL
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAPCAL-Azure
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAPCAL-EC2
libapr1-1.6.3-150000.3.6.1
Image SLES15-SP6-SAPCAL-GCE
libapr1-1.6.3-150000.3.6.1
Image proxy-httpd-image
libapr1-1.6.3-150000.3.6.1
Image server-image
libapr1-1.6.3-150000.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
apr-devel-1.6.3-150000.3.6.1
libapr1-1.6.3-150000.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
apr-devel-1.6.3-150000.3.6.1
libapr1-1.6.3-150000.3.6.1
openSUSE Leap 15.5
apr-devel-1.6.3-150000.3.6.1
libapr1-1.6.3-150000.3.6.1
openSUSE Leap 15.6
apr-devel-1.6.3-150000.3.6.1
libapr1-1.6.3-150000.3.6.1

Описание

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.


Затронутые продукты
Container bci/php-apache:latest:libapr1-1.6.3-150000.3.6.1
Container containers/apache-tomcat:10.1-openjdk11:libapr1-1.6.3-150000.3.6.1
Container containers/apache-tomcat:10.1-openjdk17:libapr1-1.6.3-150000.3.6.1
Container containers/apache-tomcat:10.1-openjdk21:libapr1-1.6.3-150000.3.6.1

Ссылки