SUSE: 2023:4056-1 suse/sle15 Security Update
Summary
Advisory ID: SUSE-SU-2023:4650-1 Released: Wed Dec 6 11:09:31 2023 Summary: Security update for curl Type: security Severity: moderate Advisory ID: SUSE-SU-2023:4672-1 Released: Wed Dec 6 14:37:37 2023 Summary: Security update for suse-build-key Type: security Severity: important
References
References : 1215889 1216410 1217215 1217573 CVE-2023-38546 CVE-2023-46218
1215889,1217573,CVE-2023-38546,CVE-2023-46218
This update for curl fixes the following issues:
- CVE-2023-38546: Fixed a cookie injection with none file (bsc#1215889).
- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).
1216410,1217215
This update for suse-build-key fixes the following issues:
This update runs a import-suse-build-key script.
The previous libzypp-post-script based installation is replaced
with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777).
- suse-build-key-import.service
- suse-build-key-import.timer
It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys.
After successful import the timer is disabled.
To manually import them you can also run:
# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc
# rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc
The following package changes have been done:
- libcurl4-7.60.0-150000.56.1 updated
- suse-build-key-12.0-150000.8.37.1 updated