Container summary for containers/apache-tomcat


SUSE-CU-2024:4694-1

Container Advisory IDSUSE-CU-2024:4694-1
Container Tagscontainers/apache-tomcat:10.1-openjdk21 , containers/apache-tomcat:10.1-openjdk21-51.5 , containers/apache-tomcat:10.1.25-openjdk21
Container Release51.5
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3476-1
ReleasedFri Sep 27 15:16:38 2024
SummaryRecommended update for curl
Typerecommended
Severitymoderate
References1230516
Description:

This update for curl fixes the following issue:


SUSE-CU-2024:4551-1

Container Advisory IDSUSE-CU-2024:4551-1
Container Tagscontainers/apache-tomcat:10.1-openjdk21 , containers/apache-tomcat:10.1-openjdk21-49.1 , containers/apache-tomcat:10.1.25-openjdk21
Container Release49.1
The following patches have been included in this update:

SUSE-CU-2024:4520-1

Container Advisory IDSUSE-CU-2024:4520-1
Container Tagscontainers/apache-tomcat:10.1-openjdk21 , containers/apache-tomcat:10.1-openjdk21-48.3 , containers/apache-tomcat:10.1.25-openjdk21 , containers/apache-tomcat:10.1.25-openjdk21-48.3
Container Release48.3
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3300-1
ReleasedWed Sep 18 14:27:53 2024
SummaryRecommended update for ncurses
Typerecommended
Severitymoderate
References1229028
Description:

This update for ncurses fixes the following issues:


SUSE-CU-2024:4387-1

Container Advisory IDSUSE-CU-2024:4387-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-46.1 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-46.1 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-46.1
Container Release46.1
The following patches have been included in this update:

SUSE-CU-2024:4342-1

Container Advisory IDSUSE-CU-2024:4342-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-45.2 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-45.2 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-45.2
Container Release45.2
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3239-1
ReleasedFri Sep 13 12:00:58 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1229476
Description:

This update for util-linux fixes the following issue:


SUSE-CU-2024:4262-1

Container Advisory IDSUSE-CU-2024:4262-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-45.1 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-45.1 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-45.1
Container Release45.1
The following patches have been included in this update:

SUSE-CU-2024:4256-1

Container Advisory IDSUSE-CU-2024:4256-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-44.3 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-44.3 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-44.3
Container Release44.3
The following patches have been included in this update:

SUSE-CU-2024:4248-1

Container Advisory IDSUSE-CU-2024:4248-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-43.7 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-43.7 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-43.7
Container Release43.7
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3204-1
ReleasedWed Sep 11 10:55:22 2024
SummarySecurity update for curl
Typesecurity
Severitymoderate
References1230093,CVE-2024-8096
Description:

This update for curl fixes the following issues:


SUSE-CU-2024:4164-1

Container Advisory IDSUSE-CU-2024:4164-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-43.6 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-43.6 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-43.6
Container Release43.6
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3106-1
ReleasedTue Sep 3 17:00:40 2024
SummarySecurity update for openssl-3
Typesecurity
Severitymoderate
References1220523,1220690,1220693,1220696,1221365,1221751,1221752,1221753,1221760,1221786,1221787,1221821,1221822,1221824,1221827,1229465,CVE-2024-6119
Description:

This update for openssl-3 fixes the following issues:


Other fixes:


Advisory IDSUSE-RU-2024:3132-1
ReleasedTue Sep 3 17:43:10 2024
SummaryRecommended update for permissions
Typerecommended
Severitymoderate
References1228968,1229329
Description:

This update for permissions fixes the following issues:



Advisory IDSUSE-RU-2024:3166-1
ReleasedMon Sep 9 12:25:30 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1228042
Description:

This update for glibc fixes the following issue:


SUSE-CU-2024:3950-1

Container Advisory IDSUSE-CU-2024:3950-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-43.3 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-43.3 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-43.3
Container Release43.3
The following patches have been included in this update:

SUSE-CU-2024:3909-1

Container Advisory IDSUSE-CU-2024:3909-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-43.2 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-43.2 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-43.2
Container Release43.2
The following patches have been included in this update:

SUSE-CU-2024:3874-1

Container Advisory IDSUSE-CU-2024:3874-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-43.2 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-43.2 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-43.2
Container Release43.2
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2967-1
ReleasedMon Aug 19 15:41:29 2024
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1194818
Description:

This update for pam fixes the following issue:


SUSE-CU-2024:3786-1

Container Advisory IDSUSE-CU-2024:3786-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-43.1 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-43.1 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-43.1
Container Release43.1
The following patches have been included in this update:
Advisory IDSUSE-SU-2019:3086-1
ReleasedThu Nov 28 10:02:24 2019
SummarySecurity update for libidn2
Typesecurity
Severitymoderate
References1154884,1154887,CVE-2019-12290,CVE-2019-18224
Description:

This update for libidn2 to version 2.2.0 fixes the following issues:


Advisory IDSUSE-RU-2020:3942-1
ReleasedTue Dec 29 12:22:01 2020
SummaryRecommended update for libidn2
Typerecommended
Severitymoderate
References1180138
Description:

This update for libidn2 fixes the following issues:


Advisory IDSUSE-SU-2021:3942-1
ReleasedMon Dec 6 14:46:05 2021
SummarySecurity update for brotli
Typesecurity
Severitymoderate
References1175825,CVE-2020-8927
Description:

This update for brotli fixes the following issues:


Advisory IDSUSE-RU-2022:1658-1
ReleasedFri May 13 15:40:20 2022
SummaryRecommended update for libpsl
Typerecommended
Severityimportant
References1197771
Description:

This update for libpsl fixes the following issues:


Advisory IDSUSE-SU-2024:2784-1
ReleasedTue Aug 6 14:58:38 2024
SummarySecurity update for curl
Typesecurity
Severityimportant
References1227888,1228535,CVE-2024-6197,CVE-2024-7264
Description:

This update for curl fixes the following issues:


SUSE-CU-2024:3692-1

Container Advisory IDSUSE-CU-2024:3692-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-41.3 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-41.3 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-41.3
Container Release41.3
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2888-1
ReleasedTue Aug 13 11:07:41 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1159034,1194818,1218609,1222285
Description:

This update for util-linux fixes the following issues:


SUSE-CU-2024:3626-1

Container Advisory IDSUSE-CU-2024:3626-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-41.2 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-41.2 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-41.2
Container Release41.2
The following patches have been included in this update:

SUSE-CU-2024:3555-1

Container Advisory IDSUSE-CU-2024:3555-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-39.6 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-39.6 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-39.6
Container Release39.6
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2808-1
ReleasedWed Aug 7 09:49:32 2024
SummarySecurity update for shadow
Typesecurity
Severitymoderate
References1228770,CVE-2013-4235
Description:

This update for shadow fixes the following issues:


SUSE-CU-2024:3478-1

Container Advisory IDSUSE-CU-2024:3478-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-39.4 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-39.4 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-39.4
Container Release39.4
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2779-1
ReleasedTue Aug 6 14:35:49 2024
SummaryRecommended update for permissions
Typerecommended
Severitymoderate
References1228548
Description:


This update for permissions fixes the following issue:


Advisory IDSUSE-RU-2024:2791-1
ReleasedTue Aug 6 16:35:06 2024
SummaryRecommended update for various 32bit packages
Typerecommended
Severitymoderate
References1228322
Description:


This update of various packages delivers 32bit variants to allow running Wine on SLE PackageHub 15 SP6.


SUSE-CU-2024:3477-1

Container Advisory IDSUSE-CU-2024:3477-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-39.1 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-39.1 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-39.1
Container Release39.1
The following patches have been included in this update:

SUSE-CU-2024:3409-1

Container Advisory IDSUSE-CU-2024:3409-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-38.1 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-38.1 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-38.1
Container Release38.1
The following patches have been included in this update:

SUSE-CU-2024:3346-1

Container Advisory IDSUSE-CU-2024:3346-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-37.3 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-37.3 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-37.3
Container Release37.3
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2684-1
ReleasedWed Jul 31 20:04:41 2024
SummaryRecommended update for mozilla-nss
Typerecommended
Severitymoderate
References1214980,1222804,1222807,1222811,1222813,1222814,1222821,1222822,1222826,1222828,1222830,1222833,1222834,1223724,1224113,1224115,1224116,1224118,1227918,CVE-2023-5388
Description:

This update for mozilla-nss fixes the following issues:




Update to NSS 3.101.2:



update to NSS 3.101.1:

update to NSS 3.101:


Update to NSS 3.100:

Update to NSS 3.99:

Update to NSS 3.98:

Update to NSS 3.97:

Update to NSS 3.96.1:

Update to NSS 3.95:

Update to NSS 3.94:

Update to NSS 3.93:

Update to NSS 3.92:

Update to NSS 3.91:

Update to NSS 3.90.3:


SUSE-CU-2024:3316-1

Container Advisory IDSUSE-CU-2024:3316-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-37.2 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-37.2 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-37.2
Container Release37.2
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2630-1
ReleasedTue Jul 30 09:12:44 2024
SummarySecurity update for shadow
Typesecurity
Severityimportant
References916845,CVE-2013-4235
Description:

This update for shadow fixes the following issues:


Advisory IDSUSE-SU-2024:2635-1
ReleasedTue Jul 30 09:14:09 2024
SummarySecurity update for openssl-3
Typesecurity
Severityimportant
References1222899,1223336,1226463,1227138,CVE-2024-5535
Description:

This update for openssl-3 fixes the following issues:
Security fixes:


Other fixes:


Advisory IDSUSE-RU-2024:2667-1
ReleasedTue Jul 30 16:14:01 2024
SummaryRecommended update for libxkbcommon
Typerecommended
Severitymoderate
References1218640,1228322
Description:


This update of libxkbcommon fixes the following issue:


SUSE-CU-2024:3254-1

Container Advisory IDSUSE-CU-2024:3254-1
Container Tagscontainers/apache-tomcat:10-jre21 , containers/apache-tomcat:10-jre21-36.2 , containers/apache-tomcat:10.1-jre21 , containers/apache-tomcat:10.1-jre21-36.2 , containers/apache-tomcat:10.1.25-jre21 , containers/apache-tomcat:10.1.25-jre21-36.2
Container Release36.2
The following patches have been included in this update:
Advisory IDSUSE-RU-2018:2307-1
ReleasedThu Oct 18 14:42:54 2018
SummaryRecommended update for libxcb
Typerecommended
Severitymoderate
References1101560
Description:

This update for libxcb provides the following fix:


Advisory IDSUSE-RU-2018:2569-1
ReleasedFri Nov 2 19:00:18 2018
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1110700
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2018:2607-1
ReleasedWed Nov 7 15:42:48 2018
SummaryOptional update for gcc8
Typerecommended
Severitylow
References1084812,1084842,1087550,1094222,1102564
Description:


The GNU Compiler GCC 8 is being added to the Development Tools Module by this update.
The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
Various optimizers have been improved in GCC 8, several of bugs fixed, quite some new warnings added and the error pin-pointing and fix-suggestions have been greatly improved.
The GNU Compiler page for GCC 8 contains a summary of all the changes that have happened:
https://gcc.gnu.org/gcc-8/changes.html
Also changes needed or common pitfalls when porting software are described on:
https://gcc.gnu.org/gcc-8/porting_to.html


Advisory IDSUSE-SU-2018:2825-1
ReleasedMon Dec 3 15:35:02 2018
SummarySecurity update for pam
Typesecurity
Severityimportant
References1115640,CVE-2018-17953
Description:

This update for pam fixes the following issue:
Security issue fixed:


Advisory IDSUSE-SU-2018:2861-1
ReleasedThu Dec 6 14:32:01 2018
SummarySecurity update for ncurses
Typesecurity
Severityimportant
References1103320,1115929,CVE-2018-19211
Description:

This update for ncurses fixes the following issues:
Security issue fixed:


Non-security issue fixed:


Advisory IDSUSE-SU-2018:3044-1
ReleasedFri Dec 21 18:47:21 2018
SummarySecurity update for MozillaFirefox, mozilla-nspr and mozilla-nss
Typesecurity
Severityimportant
References1097410,1106873,1119069,1119105,CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498
Description:

This update for MozillaFirefox, mozilla-nss and mozilla-nspr fixes the following issues:
Issues fixed in MozillaFirefox:


Issues fixed in mozilla-nss:

Issues fixed in mozilla-nspr:


Advisory IDSUSE-RU-2019:44-1
ReleasedTue Jan 8 13:07:32 2019
SummaryRecommended update for acl
Typerecommended
Severitylow
References953659
Description:

This update for acl fixes the following issues:


Advisory IDSUSE-SU-2019:571-1
ReleasedThu Mar 7 18:13:46 2019
SummarySecurity update for file
Typesecurity
Severitymoderate
References1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907
Description:

This update for file fixes the following issues:
The following security vulnerabilities were addressed:


Advisory IDSUSE-SU-2019:788-1
ReleasedThu Mar 28 11:55:06 2019
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1119687,CVE-2018-20346
Description:

This update for sqlite3 to version 3.27.2 fixes the following issue:
Security issue fixed:


Release notes: https://www.sqlite.org/releaselog/3_27_2.html


Advisory IDSUSE-SU-2019:1040-1
ReleasedThu Apr 25 17:09:21 2019
SummarySecurity update for samba
Typesecurity
Severityimportant
References1114407,1124223,1125410,1126377,1131060,1131686,CVE-2019-3880
Description:

This update for samba fixes the following issues:
Security issue fixed:



ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686):


Non-security issues fixed:


Advisory IDSUSE-SU-2019:1127-1
ReleasedThu May 2 09:39:24 2019
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1130325,1130326,CVE-2019-9936,CVE-2019-9937
Description:

This update for sqlite3 to version 3.28.0 fixes the following issues:
Security issues fixed:


Advisory IDSUSE-SU-2019:1368-1
ReleasedTue May 28 13:15:38 2019
SummaryRecommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root
Typesecurity
Severityimportant
References1134524,CVE-2019-5021
Description:

This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:


Advisory IDSUSE-SU-2019:1372-1
ReleasedTue May 28 16:53:28 2019
SummarySecurity update for libtasn1
Typesecurity
Severitymoderate
References1105435,CVE-2018-1000654
Description:

This update for libtasn1 fixes the following issues:
Security issue fixed:


Advisory IDSUSE-RU-2019:2142-1
ReleasedWed Aug 14 18:14:04 2019
SummaryRecommended update for mozilla-nspr, mozilla-nss
Typerecommended
Severitymoderate
References1141322
Description:


This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to NSS 3.45 (bsc#1141322) :


mozilla-nspr was updated to version 4.21


Advisory IDSUSE-SU-2019:2533-1
ReleasedThu Oct 3 15:02:50 2019
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1150137,CVE-2019-16168
Description:

This update for sqlite3 fixes the following issues:
Security issue fixed:


Advisory IDSUSE-SU-2019:2997-1
ReleasedMon Nov 18 15:16:38 2019
SummarySecurity update for ncurses
Typesecurity
Severitymoderate
References1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595
Description:

This update for ncurses fixes the following issues:
Security issues fixed:


Non-security issue fixed:


Advisory IDSUSE-SU-2019:3061-1
ReleasedMon Nov 25 17:34:22 2019
SummarySecurity update for gcc9
Typesecurity
Severitymoderate
References1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536
Description:



This update includes the GNU Compiler Collection 9.
A full changelog is provided by the GCC team on:
https://www.gnu.org/software/gcc/gcc-9/changes.html

The base system compiler libraries libgcc_s1, libstdc++6 and others are now built by the gcc 9 packages.
To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 / CXX=g++-9 during configuration for using it.

Security issues fixed:


Non-security issues fixed:


Advisory IDSUSE-SU-2019:3395-1
ReleasedMon Dec 30 14:05:06 2019
SummarySecurity update for mozilla-nspr, mozilla-nss
Typesecurity
Severitymoderate
References1141322,1158527,1159819,CVE-2018-18508,CVE-2019-11745,CVE-2019-17006
Description:

This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to NSS 3.47.1:
Security issues fixed:


mozilla-nspr was updated to version 4.23:


Advisory IDSUSE-RU-2020:338-1
ReleasedThu Feb 6 13:00:23 2020
SummaryRecommended update for apr
Typerecommended
Severitymoderate
References1151059
Description:

This update for apr fixes the following issues:


Advisory IDSUSE-RU-2020:362-1
ReleasedFri Feb 7 11:14:20 2020
SummaryRecommended update for libXi
Typerecommended
Severitymoderate
References1153311
Description:


This update for libXi fixes the following issue:


Advisory IDSUSE-RU-2020:525-1
ReleasedFri Feb 28 11:49:36 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1164562
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2020:689-1
ReleasedFri Mar 13 17:09:01 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1166510
Description:


This update for PAM fixes the following issue:


Advisory IDSUSE-RU-2020:917-1
ReleasedFri Apr 3 15:02:25 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1166510
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-SU-2020:948-1
ReleasedWed Apr 8 07:44:21 2020
SummarySecurity update for gmp, gnutls, libnettle
Typesecurity
Severitymoderate
References1152692,1155327,1166881,1168345,CVE-2020-11501
Description:

This update for gmp, gnutls, libnettle fixes the following issues:
Security issue fixed:


FIPS related bugfixes:


Advisory IDSUSE-RU-2020:1226-1
ReleasedFri May 8 10:51:05 2020
SummaryRecommended update for gcc9
Typerecommended
Severitymoderate
References1149995,1152590,1167898
Description:

This update for gcc9 fixes the following issues:
This update ships the GCC 9.3 release.


Advisory IDSUSE-SU-2020:1294-1
ReleasedMon May 18 07:38:36 2020
SummarySecurity update for file
Typesecurity
Severitymoderate
References1154661,1169512,CVE-2019-18218
Description:

This update for file fixes the following issues:
Security issues fixed:


Non-security issue fixed:


Advisory IDSUSE-RU-2020:1328-1
ReleasedMon May 18 17:16:04 2020
SummaryRecommended update for grep
Typerecommended
Severitymoderate
References1155271
Description:

This update for grep fixes the following issues:


Advisory IDSUSE-SU-2020:1353-1
ReleasedWed May 20 13:02:32 2020
SummarySecurity update for freetype2
Typesecurity
Severitymoderate
References1079603,1091109,CVE-2018-6942
Description:

This update for freetype2 to version 2.10.1 fixes the following issues:
Security issue fixed:


Non-security issues fixed:









Advisory IDSUSE-SU-2020:1677-1
ReleasedThu Jun 18 18:16:39 2020
SummarySecurity update for mozilla-nspr, mozilla-nss
Typesecurity
Severityimportant
References1159819,1169746,1171978,CVE-2019-17006,CVE-2020-12399
Description:

This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to version 3.53

Release notes: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53_release_notes
mozilla-nspr to version 4.25


Advisory IDSUSE-RU-2020:1852-1
ReleasedMon Jul 6 16:50:23 2020
SummaryRecommended update for fontforge, ghostscript-fonts, ttf-converter, xorg-x11-fonts
Typerecommended
Severitymoderate
References1169444
Description:

This update for fontforge, ghostscript-fonts, ttf-converter, xorg-x11-fonts fixes the following issues:
Changes in fontforge:


Changes in ttf-converter:

--shift-unicode-values: When passed 3 comma separated numbers a,b,c this shifts the unicode values of glyphs between a and b (both included) by adding c. Can be used more than once. * Add --bitmapTransform parameter to transform bitmap glyphs. (bsc#1169444) When used, all glyphs are modified with the transformation function and values passed as parameters. The parameter has three values separated by commas: fliph|flipv|rotate90cw|rotate90ccw|rotate180|skew|transmove,xoff,yoff * Add support to convert bitmap fonts (bsc#1169444) * Rename MediumItalic subfamily to Medium Italic * Show some more information when removing duplicated glyphs * Add a --force-monospaced argument instead of hardcoding font names * Convert `BoldCond` subfamily to `Bold Condensed` * Fixes for Monospaced fonts and force the Nimbus Mono L font to be Monospaced. (bsc#1169444 #c41) * Add a --version argument * Fix subfamily names so the converted font's subfamily match the original ones. (bsc#1169444 #c41)
Changes in xorg-x11-fonts:

Changes in ghostscript-fonts:


Advisory IDSUSE-RU-2020:2083-1
ReleasedThu Jul 30 10:27:59 2020
SummaryRecommended update for diffutils
Typerecommended
Severitymoderate
References1156913
Description:

This update for diffutils fixes the following issue:


Advisory IDSUSE-SU-2020:2116-1
ReleasedTue Aug 4 15:12:41 2020
SummarySecurity update for libX11
Typesecurity
Severityimportant
References1174628,CVE-2020-14344
Description:

This update for libX11 fixes the following issues:


Advisory IDSUSE-SU-2020:2947-1
ReleasedFri Oct 16 15:23:07 2020
SummarySecurity update for gcc10, nvptx-tools
Typesecurity
Severitymoderate
References1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844
Description:

This update for gcc10, nvptx-tools fixes the following issues:
This update provides the GCC10 compiler suite and runtime libraries.
The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by the gcc10 variants.
The new compiler variants are available with '-10' suffix, you can specify them via:
CC=gcc-10 CXX=g++-10
or similar commands.
For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
Changes in nvptx-tools:


Advisory IDSUSE-RU-2020:2983-1
ReleasedWed Oct 21 15:03:03 2020
SummaryRecommended update for file
Typerecommended
Severitymoderate
References1176123
Description:

This update for file fixes the following issues:


Advisory IDSUSE-SU-2020:2995-1
ReleasedThu Oct 22 10:03:09 2020
SummarySecurity update for freetype2
Typesecurity
Severityimportant
References1177914,CVE-2020-15999
Description:

This update for freetype2 fixes the following issues:


Advisory IDSUSE-SU-2020:3091-1
ReleasedThu Oct 29 16:35:37 2020
SummarySecurity update for MozillaThunderbird and mozilla-nspr
Typesecurity
Severityimportant
References1174230,1176384,1176756,1176899,1177977,CVE-2020-15673,CVE-2020-15676,CVE-2020-15677,CVE-2020-15678,CVE-2020-15683,CVE-2020-15969
Description:

This update for MozillaThunderbird and mozilla-nspr fixes the following issues:



Advisory IDSUSE-RU-2020:3462-1
ReleasedFri Nov 20 13:14:35 2020
SummaryRecommended update for pam and sudo
Typerecommended
Severitymoderate
References1174593,1177858,1178727
Description:

This update for pam and sudo fixes the following issue:
pam:


sudo:


Advisory IDSUSE-RU-2020:3620-1
ReleasedThu Dec 3 17:03:55 2020
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2021:220-1
ReleasedTue Jan 26 14:00:51 2021
SummaryRecommended update for keyutils
Typerecommended
Severitymoderate
References1180603
Description:

This update for keyutils fixes the following issues:


Advisory IDSUSE-RU-2021:293-1
ReleasedWed Feb 3 12:52:34 2021
SummaryRecommended update for gmp
Typerecommended
Severitymoderate
References1180603
Description:

This update for gmp fixes the following issues:


Advisory IDSUSE-OU-2021:339-1
ReleasedMon Feb 8 13:16:07 2021
SummaryOptional update for pam
Typeoptional
Severitylow
References
Description:

This update for pam fixes the following issues:


This patch is optional to be installed - it doesn't fix any bugs.


Advisory IDSUSE-RU-2021:924-1
ReleasedTue Mar 23 10:00:49 2021
SummaryRecommended update for filesystem
Typerecommended
Severitymoderate
References1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094
Description:

This update for filesystem the following issues:


This update for systemd fixes the following issues:


Advisory IDSUSE-SU-2021:1007-1
ReleasedThu Apr 1 17:47:20 2021
SummarySecurity update for MozillaFirefox
Typesecurity
Severityimportant
References1183942,CVE-2021-23981,CVE-2021-23982,CVE-2021-23984,CVE-2021-23987
Description:

This update for MozillaFirefox fixes the following issues:


Advisory IDSUSE-SU-2021:1409-1
ReleasedWed Apr 28 16:32:50 2021
SummarySecurity update for giflib
Typesecurity
Severitylow
References1184123
Description:

This update for giflib fixes the following issues:


Advisory IDSUSE-RU-2021:1643-1
ReleasedWed May 19 13:51:48 2021
SummaryRecommended update for pam
Typerecommended
Severityimportant
References1181443,1184358,1185562
Description:

This update for pam fixes the following issues:


Advisory IDSUSE-RU-2021:1861-1
ReleasedFri Jun 4 09:59:40 2021
SummaryRecommended update for gcc10
Typerecommended
Severitymoderate
References1029961,1106014,1178577,1178624,1178675,1182016
Description:

This update for gcc10 fixes the following issues:


Advisory IDSUSE-RU-2021:2173-1
ReleasedMon Jun 28 14:59:45 2021
SummaryRecommended update for automake
Typerecommended
Severitymoderate
References1040589,1047218,1182604,1185540,1186049
Description:

This update for automake fixes the following issues:


This update for pcre fixes the following issues:

This update for brp-check-suse fixes the following issues:


Advisory IDSUSE-SU-2021:2320-1
ReleasedWed Jul 14 17:01:06 2021
SummarySecurity update for sqlite3
Typesecurity
Severityimportant
References1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327
Description:

This update for sqlite3 fixes the following issues:


Advisory IDSUSE-RU-2021:3115-1
ReleasedThu Sep 16 14:04:26 2021
SummaryRecommended update for mozilla-nspr, mozilla-nss
Typerecommended
Severitymoderate
References1029961,1174697,1176206,1176934,1179382,1188891,CVE-2020-12400,CVE-2020-12401,CVE-2020-12403,CVE-2020-25648,CVE-2020-6829
Description:

This update for mozilla-nspr fixes the following issues:
mozilla-nspr was updated to version 4.32:



Mozilla NSS was updated to version 3.68:

update to NSS 3.67

update to NSS 3.66

update to NSS 3.65

update to NSS 3.64
disable_crypto_vsx.
  • bmo#1698320 - replace __builtin_cpu_supports('vsx') with
  • ppc_crypto_support() for clang.
  • bmo#1613235 - Add POWER ChaCha20 stream cipher vector
  • acceleration.
    Fixed in 3.63
    initialization to prevent build isses with GCC 4.8.
  • bmo#1683520 - [lib/freebl/ecl] P-384: allow zero scalars in dual
  • scalar multiplication.
  • bmo#1683520 - ECCKiila P521, change syntax of nested structs
  • initialization to prevent build isses with GCC 4.8.
  • bmo#1683520 - [lib/freebl/ecl] P-521: allow zero scalars in dual
  • scalar multiplication.
  • bmo#1696800 - HACL* update March 2021 - c95ab70fcb2bc21025d8845281bc4bc8987ca683.
  • bmo#1694214 - tstclnt can't enable middlebox compat mode.
  • bmo#1694392 - NSS does not work with PKCS #11 modules not supporting
  • profiles.
  • bmo#1685880 - Minor fix to prevent unused variable on early return.
  • bmo#1685880 - Fix for the gcc compiler version 7 to support setenv
  • with nss build.
  • bmo#1693217 - Increase nssckbi.h version number for March 2021 batch
  • of root CA changes, CA list version 2.48.
  • bmo#1692094 - Set email distrust after to 21-03-01 for Camerfirma's
  • 'Chambers of Commerce' and 'Global Chambersign' roots.
  • bmo#1618407 - Symantec root certs - Set CKA_NSS_EMAIL_DISTRUST_AFTER.
  • bmo#1693173 - Add GlobalSign R45, E45, R46, and E46 root certs to NSS.
  • bmo#1683738 - Add AC RAIZ FNMT-RCM SERVIDORES SEGUROS root cert to NSS.
  • bmo#1686854 - Remove GeoTrust PCA-G2 and VeriSign Universal root certs
  • from NSS.
  • bmo#1687822 - Turn off Websites trust bit for the “Staat der
  • Nederlanden Root CA - G3” root cert in NSS.
  • bmo#1692094 - Turn off Websites Trust Bit for 'Chambers of Commerce
  • Root - 2008' and 'Global Chambersign Root - 2008’.
  • bmo#1694291 - Tracing fixes for ECH.

  • update to NSS 3.62
    can corrupt 'cachedCertTable'
  • bmo#1690583 - Fix CH padding extension size calculation
  • bmo#1690421 - Adjust 3.62 ABI report formatting for new libabigail
  • bmo#1690421 - Install packaged libabigail in docker-builds image
  • bmo#1689228 - Minor ECH -09 fixes for interop testing, fuzzing
  • bmo#1674819 - Fixup a51fae403328, enum type may be signed
  • bmo#1681585 - Add ECH support to selfserv
  • bmo#1681585 - Update ECH to Draft-09
  • bmo#1678398 - Add Export/Import functions for HPKE context
  • bmo#1678398 - Update HPKE to draft-07

  • update to NSS 3.61
    values under certain conditions.
  • bmo#1684300 - Fix default PBE iteration count when NSS is compiled
  • with NSS_DISABLE_DBM.
  • bmo#1651411 - Improve constant-timeness in RSA operations.
  • bmo#1677207 - Upgrade Google Test version to latest release.
  • bmo#1654332 - Add aarch64-make target to nss-try.

  • Update to NSS 3.60.1:
    Notable changes in NSS 3.60:
    Update to NSS 3.59.1:
    PKCS11 modules
    Update to NSS 3.59:
    Notable changes:

    Bugfixes
    root certs when SHA1 signatures are disabled.
  • bmo#1644209 - Fix broken SelectedCipherSuiteReplacer filter to
  • solve some test intermittents
  • bmo#1672703 - Tolerate the first CCS in TLS 1.3 to fix a regression in
  • our CVE-2020-25648 fix that broke purple-discord (boo#1179382)
  • bmo#1666891 - Support key wrap/unwrap with RSA-OAEP
  • bmo#1667989 - Fix gyp linking on Solaris
  • bmo#1668123 - Export CERT_AddCertToListHeadWithData and
  • CERT_AddCertToListTailWithData from libnss
  • bmo#1634584 - Set CKA_NSS_SERVER_DISTRUST_AFTER for Trustis FPS Root CA
  • bmo#1663091 - Remove unnecessary assertions in the streaming
  • ASN.1 decoder that affected decoding certain PKCS8 private keys when using NSS debug builds
  • bmo#670839 - Use ARM crypto extension for AES, SHA1 and SHA2 on MacOS.

  • update to NSS 3.58
    Bugs fixed:

    update to NSS 3.57

    update to NSS 3.56
    Notable changes
    detection.
  • bmo#1652729 - Add build flag to disable RC2 and relocate to
  • lib/freebl/deprecated.
  • bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay.
  • bmo#1588941 - Send empty certificate message when scheme selection
  • fails.
  • bmo#1652032 - Fix failure to build in Windows arm64 makefile
  • cross-compilation.
  • bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent.
  • bmo#1653975 - Fix 3.53 regression by setting 'all' as the default
  • makefile target.
  • bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert.
  • bmo#1659814 - Fix interop.sh failures with newer tls-interop
  • commit and dependencies.
  • bmo#1656519 - NSPR dependency updated to 4.28

  • update to NSS 3.55
    Notable changes
    Relevant Bugfixes

    update to NSS 3.54
    Notable changes


    Bugs fixed
    Root Certification Authority; C=TW' root.
  • bmo#1645199 - Remove AddTrust root certificates.
  • bmo#1641718 - Remove 'LuxTrust Global Root 2' root certificate.
  • bmo#1639987 - Remove 'Staat der Nederlanden Root CA - G2' root
  • certificate.
  • bmo#1618402 - Remove Symantec root certificates and disable email trust
  • bit.
  • bmo#1640516 - NSS 3.54 should depend on NSPR 4.26.
  • bmo#1642146 - Fix undefined reference to `PORT_ZAlloc_stub' in seed.c.
  • bmo#1642153 - Fix infinite recursion building NSS.
  • bmo#1642638 - Fix fuzzing assertion crash.
  • bmo#1642871 - Enable SSL_SendSessionTicket after resumption.
  • bmo#1643123 - Support SSL_ExportEarlyKeyingMaterial with External PSKs.
  • bmo#1643557 - Fix numerous compile warnings in NSS.
  • bmo#1644774 - SSL gtests to use ClearServerCache when resetting
  • self-encrypt keys.
  • bmo#1645479 - Don't use SECITEM_MakeItem in secutil.c.
  • bmo#1646520 - Stricter enforcement of ASN.1 INTEGER encoding.

  • Advisory IDSUSE-RU-2021:3182-1
    ReleasedTue Sep 21 17:04:26 2021
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1189996
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-SU-2021:3490-1
    ReleasedWed Oct 20 16:31:55 2021
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1190793,CVE-2021-39537
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2021:3494-1
    ReleasedWed Oct 20 16:48:46 2021
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1190052
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2021:3510-1
    ReleasedTue Oct 26 11:22:15 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1191987
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2021:3529-1
    ReleasedWed Oct 27 09:23:32 2021
    SummarySecurity update for pcre
    Typesecurity
    Severitymoderate
    References1172973,1172974,CVE-2019-20838,CVE-2020-14155
    Description:

    This update for pcre fixes the following issues:
    Update pcre to version 8.45:


    Advisory IDSUSE-RU-2021:3799-1
    ReleasedWed Nov 24 18:07:54 2021
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1187153,1187273,1188623
    Description:

    This update for gcc11 fixes the following issues:
    The additional GNU compiler collection GCC 11 is provided:
    To select these compilers install the packages:


    to select them for building:

    The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.


    Advisory IDSUSE-RU-2021:3891-1
    ReleasedFri Dec 3 10:21:49 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1029961,1113013,1187654
    Description:

    This update for keyutils fixes the following issues:


    keyutils was updated to 1.6.3 (jsc#SLE-20016):

    Updated to 1.6:

    Updated to 1.5.11 (bsc#1113013)


    Advisory IDSUSE-SU-2021:3946-1
    ReleasedMon Dec 6 14:57:42 2021
    SummarySecurity update for gmp
    Typesecurity
    Severitymoderate
    References1192717,CVE-2021-43618
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-SU-2021:4107-1
    ReleasedThu Dec 16 19:02:22 2021
    SummarySecurity update for log4j
    Typesecurity
    Severityimportant
    References1193743,CVE-2021-44228,CVE-2021-45046
    Description:

    This update for log4j fixes the following issue:


    Advisory IDSUSE-RU-2022:12-1
    ReleasedMon Jan 3 15:36:04 2022
    SummaryRecommended update for cairo, jbigkit, libjpeg-turbo, libwebp, libxcb, openjpeg2, pixman, poppler, tiff
    Typerecommended
    Severitymoderate
    References
    Description:

    This recommended update for cairo, jbigkit, libjpeg-turbo, libwebp, libxcb, openjpeg2, pixman, poppler, tiff provides the following fix:


    Advisory IDSUSE-RU-2022:692-1
    ReleasedThu Mar 3 15:46:47 2022
    SummaryRecommended update for filesystem
    Typerecommended
    Severitymoderate
    References1190447
    Description:

    This update for filesystem fixes the following issues:


    Advisory IDSUSE-RU-2022:789-1
    ReleasedThu Mar 10 11:22:05 2022
    SummaryRecommended update for update-alternatives
    Typerecommended
    Severitymoderate
    References1195654
    Description:

    This update for update-alternatives fixes the following issues:


    Advisory IDSUSE-RU-2022:861-1
    ReleasedTue Mar 15 23:31:21 2022
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1182959,1195149,1195792,1195856
    Description:

    This update for openssl-1_1 fixes the following issues:
    openssl-1_1:

    glibc:
    linux-glibc-devel:

    libxcrypt:

    zlib:


    Advisory IDSUSE-RU-2022:936-1
    ReleasedTue Mar 22 18:10:17 2022
    SummaryRecommended update for filesystem and systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1196275,1196406
    Description:

    This update for filesystem and systemd-rpm-macros fixes the following issues:
    filesystem:


    systemd-rpm-macros:


    Advisory IDSUSE-RU-2022:1047-1
    ReleasedWed Mar 30 16:20:56 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1196093,1197024
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2022:1281-1
    ReleasedWed Apr 20 12:26:38 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:1409-1
    ReleasedTue Apr 26 12:54:57 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1195628,1196107
    Description:

    This update for gcc11 fixes the following issues:


    Advisory IDSUSE-SU-2022:1565-1
    ReleasedFri May 6 17:09:36 2022
    SummarySecurity update for giflib
    Typesecurity
    Severitymoderate
    References1094832,1146299,1184123,974847,CVE-2016-3977,CVE-2018-11490,CVE-2019-15133
    Description:

    This update for giflib fixes the following issues:

    Update to version 5.2.1 * In gifbuild.c, avoid a core dump on no color map. * Restore inadvertently removed library version numbers in Makefile. Changes in version 5.2.0 * The undocumented and deprecated GifQuantizeBuffer() entry point has been moved to the util library to reduce libgif size and attack surface. Applications needing this function are couraged to link the util library or make their own copy. * The following obsolete utility programs are no longer installed: gifecho, giffilter, gifinto, gifsponge. These were either installed in error or have been obsolesced by modern image-transformmation tools like ImageMagick convert. They may be removed entirely in a future release. * Address SourceForge issue #136: Stack-buffer-overflow in gifcolor.c:84 * Address SF bug #134: Giflib fails to slurp significant number of gifs * Apply SPDX convention for license tagging. Changes in version 5.1.9 * The documentation directory now includes an HTMlified version of the GIF89 standard, and a more detailed description of how LZW compression is applied to GIFs. * Address SF bug #129: The latest version of giflib cannot be build on windows. * Address SF bug #126: Cannot compile giflib using c89 Changes in version 5.1.8 * Address SF bug #119: MemorySanitizer: FPE on unknown address (CVE-2019-15133 bsc#1146299) * Address SF bug #125: 5.1.7: xmlto is still required for tarball * Address SF bug #124: 5.1.7: ar invocation is not crosscompile compatible * Address SF bug #122: 5.1.7 installs manpages to wrong directory * Address SF bug #121: make: getversion: Command not found * Address SF bug #120: 5.1.7 does not build a proper library - no Changes in version 5.1.7 * Correct a minor packaging error (superfluous symlinks) in the 5.1.6 tarballs. Changes in version 5.1.6 * Fix library installation in the Makefile. Changes in version 5.1.5 * Fix SF bug #114: Null dereferences in main() of gifclrmp * Fix SF bug #113: Heap Buffer Overflow-2 in function DGifDecompressLine() in cgif.c. This had been assigned (CVE-2018-11490 bsc#1094832). * Fix SF bug #111: segmentation fault in PrintCodeBlock * Fix SF bug #109: Segmentation fault of giftool reading a crafted file * Fix SF bug #107: Floating point exception in giftext utility * Fix SF bug #105: heap buffer overflow in DumpScreen2RGB in gif2rgb.c:317 * Fix SF bug #104: Ineffective bounds check in DGifSlurp * Fix SF bug #103: GIFLIB 5.1.4: DGifSlurp fails on empty comment * Fix SF bug #87: Heap buffer overflow in 5.1.2 (gif2rgb). (CVE-2016-3977 bsc#974847) * The horrible old autoconf build system has been removed with extreme prejudice. You now build this simply by running 'make' from the top-level directory.
    The following non-security bugs were fixed:


    Advisory IDSUSE-RU-2022:1655-1
    ReleasedFri May 13 15:36:10 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1197794
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:1887-1
    ReleasedTue May 31 09:24:18 2022
    SummaryRecommended update for grep
    Typerecommended
    Severitymoderate
    References1040589
    Description:

    This update for grep fixes the following issues:


    Advisory IDSUSE-RU-2022:1899-1
    ReleasedWed Jun 1 10:43:22 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severityimportant
    References1198176
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:2019-1
    ReleasedWed Jun 8 16:50:07 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1192951,1193659,1195283,1196861,1197065
    Description:

    This update for gcc11 fixes the following issues:
    Update to the GCC 11.3.0 release.


    Advisory IDSUSE-RU-2022:2060-1
    ReleasedMon Jun 13 15:26:16 2022
    SummaryRecommended update for geronimo-specs
    Typerecommended
    Severitymoderate
    References1200426
    Description:

    This recommended update for geronimo-specs provides the following fix:


    Advisory IDSUSE-SU-2022:2294-1
    ReleasedWed Jul 6 13:34:15 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1196025,1196026,1196168,1196169,1196171,1196784,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:2361-1
    ReleasedTue Jul 12 12:05:01 2022
    SummarySecurity update for pcre
    Typesecurity
    Severityimportant
    References1199232,CVE-2022-1586
    Description:

    This update for pcre fixes the following issues:


    Advisory IDSUSE-SU-2022:2396-1
    ReleasedThu Jul 14 11:57:58 2022
    SummarySecurity update for logrotate
    Typesecurity
    Severityimportant
    References1192449,1199652,1200278,1200802,CVE-2022-1348
    Description:

    This update for logrotate fixes the following issues:
    Security issues fixed:


    Non-security issues fixed:


    Advisory IDSUSE-RU-2022:2406-1
    ReleasedFri Jul 15 11:49:01 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1197718,1199140,1200334,1200855
    Description:

    This update for glibc fixes the following issues:


    This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).


    Advisory IDSUSE-SU-2022:2533-1
    ReleasedFri Jul 22 17:37:15 2022
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
    Description:

    This update for mozilla-nss fixes the following issues:
    Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:


    Version update to NSS 3.79:

    Version update to NSS 3.78.1:

    Version update to NSS 3.78:

    Version update to NSS 3.77:

    Version update to NSS 3.76.1

    Version update to NSS 3.75

    Version update to NSS 3.74


    Version update to NSS 3.73.1:

    Version update to NSS 3.73

    Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures
    Version update to NSS 3.72

    Version update to NSS 3.71

    Version update to NSS 3.70

    Version update to NSS 3.69.1:

    NSS 3.69:

    Version Update to 3.68.4 (bsc#1200027)


    Mozilla NSPR was updated to version 4.34:


    Advisory IDSUSE-SU-2022:2595-1
    ReleasedFri Jul 29 16:00:42 2022
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
    Description:

    This update for mozilla-nss fixes the following issues:
    Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:


    Version update to NSS 3.79:

    Version update to NSS 3.78.1:

    Version update to NSS 3.78:

    Version update to NSS 3.77:

    Version update to NSS 3.76.1

    Version update to NSS 3.75

    Version update to NSS 3.74


    Version update to NSS 3.73.1:

    Version update to NSS 3.73

    Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures
    Version update to NSS 3.72

    Version update to NSS 3.71

    Version update to NSS 3.70

    Version update to NSS 3.69.1:

    NSS 3.69:

    Version Update to 3.68.4 (bsc#1200027)


    Advisory IDSUSE-SU-2022:2632-1
    ReleasedWed Aug 3 09:51:00 2022
    SummarySecurity update for permissions
    Typesecurity
    Severityimportant
    References1198720,1200747,1201385
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:2717-1
    ReleasedTue Aug 9 12:54:16 2022
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1198627,CVE-2022-29458
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2022:2796-1
    ReleasedFri Aug 12 14:34:31 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for jitterentropy fixes the following issues:
    jitterentropy is included in version 3.4.0 (jsc#SLE-24941):
    This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library, used by other FIPS libraries.


    Advisory IDSUSE-RU-2022:2939-1
    ReleasedMon Aug 29 14:49:17 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1201298,1202645
    Description:

    This update for mozilla-nss fixes the following issues:
    Update to NSS 3.79.1 (bsc#1202645)



    Advisory IDSUSE-RU-2022:2994-1
    ReleasedFri Sep 2 10:44:54 2022
    SummaryRecommended update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau, libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame
    Typerecommended
    Severitymoderate
    References1198925
    Description:


    This update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau, libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame adds some missing 32bit libraries to some products. (bsc#1198925)
    No codechanges were done in this update.


    Advisory IDSUSE-RU-2022:3127-1
    ReleasedWed Sep 7 04:36:10 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1198752,1200800
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2022:3252-1
    ReleasedMon Sep 12 09:07:53 2022
    SummarySecurity update for freetype2
    Typesecurity
    Severitymoderate
    References1198823,1198830,1198832,CVE-2022-27404,CVE-2022-27405,CVE-2022-27406
    Description:

    This update for freetype2 fixes the following issues:


    Non-security fixes:


    Advisory IDSUSE-RU-2022:3262-1
    ReleasedTue Sep 13 15:34:29 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1199140
    Description:


    This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)


    Advisory IDSUSE-SU-2022:3305-1
    ReleasedMon Sep 19 11:45:57 2022
    SummarySecurity update for libtirpc
    Typesecurity
    Severityimportant
    References1201680,CVE-2021-46828
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2022:3307-1
    ReleasedMon Sep 19 13:26:51 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2022:3328-1
    ReleasedWed Sep 21 12:48:56 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1202870
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-SU-2022:3353-1
    ReleasedFri Sep 23 15:23:40 2022
    SummarySecurity update for permissions
    Typesecurity
    Severitymoderate
    References1203018,CVE-2022-31252
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:3489-1
    ReleasedSat Oct 1 13:35:24 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1203438,CVE-2022-40674
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:3784-1
    ReleasedWed Oct 26 18:03:28 2022
    SummarySecurity update for libtasn1
    Typesecurity
    Severitycritical
    References1204690,CVE-2021-46848
    Description:

    This update for libtasn1 fixes the following issues:


    Advisory IDSUSE-RU-2022:3787-1
    ReleasedThu Oct 27 04:41:09 2022
    SummaryRecommended update for permissions
    Typerecommended
    Severityimportant
    References1194047,1203911
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2022:3873-1
    ReleasedFri Nov 4 14:58:08 2022
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298,1202870,1204729
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nspr was updated to version 4.34.1:


    mozilla-nss was updated to NSS 3.79.2 (bsc#1204729):

    Other fixes that were applied:


    Advisory IDSUSE-SU-2022:3884-1
    ReleasedMon Nov 7 10:59:26 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1204708,CVE-2022-43680
    Description:

    This update for expat fixes the following issues:
    - CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).


    Advisory IDSUSE-RU-2022:3910-1
    ReleasedTue Nov 8 13:05:04 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:3958-1
    ReleasedFri Nov 11 15:20:45 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298,1202870,1204729
    Description:

    This update for mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.79.2 (bsc#1204729)



    Advisory IDSUSE-SU-2022:4081-1
    ReleasedFri Nov 18 15:40:46 2022
    SummarySecurity update for dpkg
    Typesecurity
    Severitylow
    References1199944,CVE-2022-1664
    Description:

    This update for dpkg fixes the following issues:


    Advisory IDSUSE-RU-2022:4135-1
    ReleasedMon Nov 21 00:13:40 2022
    SummaryRecommended update for libeconf
    Typerecommended
    Severitymoderate
    References1198165
    Description:

    This update for libeconf fixes the following issues:



    Advisory IDSUSE-RU-2022:4256-1
    ReleasedMon Nov 28 12:36:32 2022
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
    The Go, D and Ada language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-RU-2022:4492-1
    ReleasedWed Dec 14 13:52:39 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-SU-2022:4628-1
    ReleasedWed Dec 28 09:23:13 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1206337,CVE-2022-46908
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2023:48-1
    ReleasedMon Jan 9 10:37:54 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1199467
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2023:119-1
    ReleasedFri Jan 20 10:28:07 2023
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1204272,1207038,CVE-2022-23491,CVE-2022-3479
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-SU-2023:434-1
    ReleasedThu Feb 16 09:08:05 2023
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1208138,CVE-2023-0767
    Description:

    This update for mozilla-nss fixes the following issues:
    Updated to NSS 3.79.4 (bsc#1208138):
    - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types.


    Advisory IDSUSE-SU-2023:557-1
    ReleasedTue Feb 28 09:29:15 2023
    SummarySecurity update for libxslt
    Typesecurity
    Severityimportant
    References1208574,CVE-2021-30560
    Description:

    This update for libxslt fixes the following issues:


    Advisory IDSUSE-RU-2023:617-1
    ReleasedFri Mar 3 16:49:06 2023
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1207789
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-feature-2023:775-1
    ReleasedThu Mar 16 15:58:55 2023
    SummaryFeature for updating the Java stack
    Typefeature
    Severitycritical
    References1047218,1062631,1120360,1133997,1134001,1145693,1171696,1172961,1173600,1177180,1177488,1177568,1179926,1180215,1182284,1182708,1182748,1182754,1184356,1184357,1184755,1186328,1187446,1188468,1188469,1188529,1190660,1190663,1193795,1195108,1195557,1198279,1198404,1198739,1198833,1201081,1201316,1201317,1203154,1203515,1203516,1203672,1203673,1203674,1203868,1204173,1204284,1204918,1205138,1205142,1205647,1206018,1206400,1206401,CVE-2019-17566,CVE-2020-11022,CVE-2020-11023,CVE-2020-11979,CVE-2020-11987,CVE-2020-11988,CVE-2020-13956,CVE-2020-15522,CVE-2020-1945,CVE-2020-26945,CVE-2020-28052,CVE-2020-2875,CVE-2020-2933,CVE-2020-2934,CVE-2020-8908,CVE-2021-2471,CVE-2021-26291,CVE-2021-27807,CVE-2021-27906,CVE-2021-29425,CVE-2021-33813,CVE-2021-36373,CVE-2021-36374,CVE-2021-37533,CVE-2021-42550,CVE-2021-43980,CVE-2022-2047,CVE-2022-2048,CVE-2022-23437,CVE-2022-24839,CVE-2022-28366,CVE-2022-29599,CVE-2022-37865,CVE-2022-37866,CVE-2022-38398,CVE-2022-38648,CVE-2022-38752,CVE-2022-40146,CVE-2022-40149,CVE-2022-40150,CVE-2022-42252,CVE-2022-42889,CVE-2022-45685,CVE-2022-45693
    Description:

    This feature update for the Java stack provides:
    ant:


    ant-antlr:

    ant-contrib:

    ant-junit:

    ant-junit5:

    antlr:

    antlr3:

    antlr4:

    aopalliance:

    apache-commons-beanutils:

    apache-commons-cli:

    apache-commons-codec:

    apache-commons-collections4:

    apache-commons-collections:

    apache-commons-compress:

    apache-commons-configuration:

    apache-commons-csv:

    apache-commons-daemon:

    apache-commons-dbcp:

    apache-commons-digester:

    apache-commons-el:

    apache-commons-exec:

    apache-commons-fileupload:

    apache-commons-io:

    apache-commons-jexl:

    apache-commons-lang3:

    apache-commons-logging:

    apache-commons-math:

    apache-commons-net:

    apache-commons-ognl:

    apache-commons-parent:

    apache-commons-pool2:

    apache-commons-text:

    apache-ivy:


    apache-logging-parent:

    apache-parent:

    apache-pdfbox:

    apache-resource-bundles:

    apache-sshd:

    apiguardian:

    aqute-bnd:

    args4j:

    asm3:

    atinject:

    auto:

    avalon-framework:

    avalon-logkit:

    aws-sdk-java:

    axis:

    base64coder:

    beust-jcommander:

    bnd-maven-plugin:

    bouncycastle:

    bsf:

    bsh2:

    cal10n:

    cbi-plugins:

    cdi-api:

    cglib:

    checker-qual:

    classmate:

    codemodel:

    codenarc:

    concurrentlinkedhashmap-lru:

    decentxml:

    dom4j:

    ecj:

    eclipse:

    eclipse-ecf:

    eclipse-egit:

    eclipse-emf:

    eclipse-jgit:
    eclipse-license:

    eclipse-swt:

    ed25519-java:

    ee4j:

    exec-maven-plugin:

    extra166y:

    ezmorph:

    felix-bundlerepository:

    felix-gogo-command:

    felix-gogo-runtime:

    felix-osgi-compendium:

    felix-osgi-foundation:

    felix-osgi-obr:

    felix-scr:

    felix-shell:

    felix-utils:

    fmpp:

    freemarker:

    geronimo-specs:

    glassfish-activation:

    glassfish-annotation-api:

    glassfish-dtd-parser:

    glassfish-fastinfoset:

    glassfish-jaxb-api:

    glassfish-jaxb:

    glassfish-jax-rs-api:

    glassfish-jsp:

    glassfish-servlet-api:

    glassfish-transaction-api:

    gmavenplus-plugin:

    gmetrics:

    google-errorprone-annotations:

    google-gson:

    google-guice:

    google-http-java-client:

    google-oauth-java-client:

    gpars:

    gradle-bootstrap:

    gradle:

    groovy:

    groovy18:

    guava20:

    guava:

    hamcrest:

    hawtjni-maven-plugin:

    hawtjni-runtime:

    http-builder:

    httpcomponents-client:

    httpcomponents-core:

    icu4j:

    isorelax:

    istack-commons:

    j2objc-annotations:

    jackson-modules-base:

    jackson-parent:

    jackson:

    jakarta-activation:

    jakarta-commons-discovery:


    jakarta-commons-modeler:

    jakarta-mail:

    jakarta-taglibs-standard:

    jandex:

    janino:

    jansi-native:

    jansi:

    jarjar:

    jatl:

    javacc-maven-plugin:

    javacc:

    java-cup:

    java-cup-bootstrap:
    javaewah:

    javamail:

    javapackages-meta:

    javapackages-tools:

    javaparser:

    javassist:

    jboss-interceptors-1.2-api:

    jboss-websocket-1.0-api:

    jcache:

    jcifs:

    jcip-annotations:

    jcsp:

    jctools:

    jdependency:

    jdepend:

    jdom:

    jdom2:

    jettison:

    jetty-minimal:

    jetty-websocket:

    jeuclid:

    jflex:

    jflex-bootstrap:
    jformatstring:

    jgit:

    jhighlight:

    jing-trang:

    jline:

    jline1:

    jna:

    joda-convert:

    joda-time:

    jsch-agent-proxy:

    jsch:

    json-lib:

    jsonp:

    jsr-311:

    jtidy:

    junit:

    junit5:

    jython:

    jzlib:

    kryo:

    kxml:

    libreadline-java:

    log4j:

    logback:

    lucene:

    maven:

    maven2:

    maven-antrun-plugin:

    maven-archiver:

    maven-artifact-resolver:

    maven-artifact-transfer:

    maven-assembly-plugin:

    maven-clean-plugin:

    maven-common-artifact-filters:

    maven-compiler-plugin:

    maven-dependency-analyzer:

    maven-dependency-plugin:

    maven-dependency-tree:

    maven-doxia:

    maven-doxia-sitetools:

    maven-enforcer:

    maven-file-management:

    maven-filtering:

    maven-install-plugin:

    maven-invoker:

    maven-jar-plugin:

    maven-javadoc-plugin:

    maven-mapping:

    maven-plugin-build-helper:

    maven-plugin-bundle:

    maven-plugin-testing:

    maven-plugin-tools:

    maven-remote-resources-plugin:

    maven-reporting-api:

    maven-resolver:

    maven-resources-plugin:

    maven-shared-incremental:

    maven-shared-io:

    maven-shared-utils:

    maven-source-plugin:

    maven-surefire:

    maven-verifier:

    maven-wagon:

    minlog:

    modello-maven-plugin:

    modello:

    mojo-parent:

    msv:

    multiverse:

    mx4j:

    mybatis-parent:

    mybatis:

    mysql-connector-java:

    nailgun:

    native-platform:

    nekohtml:

    netty3:

    netty-tcnative:

    objectweb-asm:

    objenesis:

    opentest4j:

    oro:

    osgi-annotation:

    osgi-compendium:

    osgi-core:

    os-maven-plugin:

    paradise:

    paranamer:

    parboiled:

    pegdown:

    picocli:

    plexus-ant-factory:

    plexus-archiver:

    plexus-bsh-factory:

    plexus-build-api:

    plexus-cipher:

    plexus-classworlds:

    plexus-cli:

    plexus-compiler:

    plexus-component-api:

    plexus-component-metadata:

    plexus-containers:

    plexus-i18n:

    plexus-interactivity:

    plexus-interpolation:

    plexus-io:

    plexus-languages:

    plexus-metadata-generator:

    plexus-resources:

    plexus-sec-dispatcher:

    plexus-utils:

    plexus-velocity:

    qdox:

    reflectasm:

    regexp:

    relaxngcc:

    relaxngDatatype:

    reload4j:

    replacer:

    rhino:

    sat4j:

    saxon9:

    sbt-launcher:

    sbt:

    scala-pickling:

    scala:

    servletapi4:

    signpost-core:

    sisu:

    slf4j:

    snakeyaml:

    spec-version-maven-plugin:

    stax2-api:

    stax-ex:

    stringtemplate4:

    string-template-maven-plugin:

    stringtemplate:
    tagsoup:

    template-resolver:

    tesla-polyglot:

    test-interface:

    testng:

    tomcat:

    treelayout:

    trilead-ssh2:

    tycho:

    univocity-parsers:

    utfcpp:

    velocity:

    werken-xpath:

    woodstox-core:

    wsdl4j:

    ws-jaxme:

    xalan-j2:

    xbean:

    xerces-j2:

    xml-commons-apis:

    xml-commons-resolver:

    xmlgraphics-batik:

    xmlgraphics-commons:

    xmlgraphics-fop:

    xml-maven-plugin:

    xmlstreambuffer:

    xmlunit:

    xmvn-connector:
    Rename xmvn-connector-aether to xmvn-connector and provide it as version 4.0.0. (jsc#SLE-23217)
    xmvn-connector-gradle:

    xmvn-connector-ivy:

    xmvn-mojo:

    xmvn-parent:

    xmvn-tools:

    xmvn:

    xpp2:

    xpp3:

    xsom:

    xstream:

    xz-java:

    zinc:


    Advisory IDSUSE-RU-2023:776-1
    ReleasedThu Mar 16 17:29:23 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
    SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes

    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided in the SUSE Linux Enterprise Module for Development Tools.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-RU-2023:1939-1
    ReleasedFri Apr 21 11:14:30 2023
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1207209,1208242,1208999
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-SU-2023:2111-1
    ReleasedFri May 5 14:34:00 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1210434,CVE-2023-29491
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-feature-2023:2269-1
    ReleasedMon May 22 14:50:34 2023
    SummaryFeature update for javapackages-tools
    Typefeature
    Severitymoderate
    References
    Description:

    This update for javapackages-tools fixes the following issues:



    Advisory IDSUSE-RU-2023:2625-1
    ReleasedFri Jun 23 17:16:11 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:


    * includes regression and other bug fixes


    Advisory IDSUSE-feature-2023:2738-1
    ReleasedFri Jun 30 05:28:49 2023
    SummaryFeature update for Apache Commons components
    Typefeature
    Severitymoderate
    References
    Description:

    This update for Apache Commons components fixes the following issues:
    apache-commons-text:


    apache-commons-daemon:

    apache-common-parent:


    Advisory IDSUSE-SU-2023:2765-1
    ReleasedMon Jul 3 20:28:14 2023
    SummarySecurity update for libcap
    Typesecurity
    Severitymoderate
    References1211418,1211419,CVE-2023-2602,CVE-2023-2603
    Description:

    This update for libcap fixes the following issues:


    Advisory IDSUSE-RU-2023:2788-1
    ReleasedThu Jul 6 11:51:02 2023
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1185116,1202118
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nspr was updated to version 4.35


    mozilla-nss was update to NSS 3.90:


    update to NSS 3.89.1

    update to NSS 3.89

    update to NSS 3.88.1

    update to NSS 3.88

    update to NSS 3.87

    update to NSS 3.86

    update to NSS 3.85

    update to NSS 3.84
    update to NSS 3.83

    update to NSS 3.82

    update to NSS 3.81



    update to NSS 3.80
    by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record.
  • Mark 3.79 as an ESR release.
  • Bump nssckbi version number for June.
  • Remove Hellenic Academic 2011 Root.
  • Add E-Tugra Roots.
  • Add Certainly Roots.
  • Add DigitCert Roots.
  • Protect SFTKSlot needLogin with slotLock.
  • Compare signature and signatureAlgorithm fields in legacy certificate verifier.
  • Uninitialized value in cert_VerifyCertChainOld.
  • Unchecked return code in sec_DecodeSigAlg.
  • Uninitialized value in cert_ComputeCertType.
  • Avoid data race on primary password change.
  • Replace ppc64 dcbzl intrinisic.
  • Allow LDFLAGS override in makefile builds.

  • Advisory IDSUSE-RU-2023:2814-1
    ReleasedWed Jul 12 22:05:25 2023
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1185116,1202118
    Description:

    This update for mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.90:



    update to NSS 3.89.1

    update to NSS 3.89

    update to NSS 3.88.1

    update to NSS 3.88

    update to NSS 3.87

    update to NSS 3.86

    update to NSS 3.85

    update to NSS 3.84

    update to NSS 3.83
    with retry configs in EncryptedExtensions and if not accepting ECH. Changed config setting behavior to skip configs with unsupported mandatory extensions instead of failing
  • Added ECH client support to BoGo shim. Changed
  • CHInner creation to skip TLS 1.2 only extensions to comply with BoGo
  • Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs
  • Update BoGo tests to recent BoringSSL version
  • Bump minimum NSPR version to 4.34.1

  • update to NSS 3.82

    update to NSS 3.81



    update to NSS 3.80
    by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record.
  • Mark 3.79 as an ESR release.
  • Bump nssckbi version number for June.
  • Remove Hellenic Academic 2011 Root.
  • Add E-Tugra Roots.
  • Add Certainly Roots.
  • Add DigitCert Roots.
  • Protect SFTKSlot needLogin with slotLock.
  • Compare signature and signatureAlgorithm fields in legacy certificate verifier.
  • Uninitialized value in cert_VerifyCertChainOld.
  • Unchecked return code in sec_DecodeSigAlg.
  • Uninitialized value in cert_ComputeCertType.
  • Avoid data race on primary password change.
  • Replace ppc64 dcbzl intrinisic.
  • Allow LDFLAGS override in makefile builds.

  • Advisory IDSUSE-RU-2023:2827-1
    ReleasedFri Jul 14 11:27:47 2023
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2023:2847-1
    ReleasedMon Jul 17 08:40:42 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1210004
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-RU-2023:2966-1
    ReleasedTue Jul 25 14:26:14 2023
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2023:3410-1
    ReleasedThu Aug 24 06:56:32 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1201519,1204844
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-SU-2023:3461-1
    ReleasedMon Aug 28 17:25:09 2023
    SummarySecurity update for freetype2
    Typesecurity
    Severitymoderate
    References1210419,CVE-2023-2004
    Description:

    This update for freetype2 fixes the following issues:


    Advisory IDSUSE-RU-2023:3611-1
    ReleasedFri Sep 15 09:28:36 2023
    SummaryRecommended update for sysuser-tools
    Typerecommended
    Severitymoderate
    References1195391,1205161,1207778,1213240,1214140
    Description:

    This update for sysuser-tools fixes the following issues:


    Advisory IDSUSE-SU-2023:3661-1
    ReleasedMon Sep 18 21:44:09 2023
    SummarySecurity update for gcc12
    Typesecurity
    Severityimportant
    References1214052,CVE-2023-4039
    Description:

    This update for gcc12 fixes the following issues:


    Advisory IDSUSE-SU-2023:3666-1
    ReleasedMon Sep 18 21:52:18 2023
    SummarySecurity update for libxml2
    Typesecurity
    Severityimportant
    References1214768,CVE-2023-39615
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2023:3954-1
    ReleasedTue Oct 3 20:09:47 2023
    SummarySecurity update for libeconf
    Typesecurity
    Severityimportant
    References1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181
    Description:

    This update for libeconf fixes the following issues:
    Update to version 0.5.2.


    Advisory IDSUSE-SU-2023:4162-1
    ReleasedMon Oct 23 15:33:03 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:


    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:




    Advisory IDSUSE-SU-2023:4215-1
    ReleasedThu Oct 26 12:19:25 2023
    SummarySecurity update for zlib
    Typesecurity
    Severitymoderate
    References1216378,CVE-2023-45853
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-RU-2023:4310-1
    ReleasedTue Oct 31 14:10:47 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This Update for libtirpc to 1.3.4, fixing the following issues: Update to 1.3.4 (bsc#1199467)
    * binddynport.c honor ip_local_reserved_ports - replaces: binddynport-honor-ip_local_reserved_ports.patch * gss-api: expose gss major/minor error in authgss_refresh() * rpcb_clnt.c: Eliminate double frees in delete_cache() * rpcb_clnt.c: memory leak in destroy_addr * portmapper: allow TCP-only portmapper * getnetconfigent: avoid potential DoS issue by removing unnecessary sleep * clnt_raw.c: fix a possible null pointer dereference * bindresvport.c: fix a potential resource leakage
    Update to 1.3.3:


    Update to 1.3.2:

    Update to 1.3.1:


    Advisory IDSUSE-SU-2023:4458-1
    ReleasedThu Nov 16 14:38:48 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:


    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:




    Advisory IDSUSE-SU-2023:4504-1
    ReleasedTue Nov 21 13:27:50 2023
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1216129,CVE-2023-45322
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2023:4617-1
    ReleasedThu Nov 30 09:37:04 2023
    SummaryRecommended update for javapackages-tools
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for javapackages-tools fixes the following issues:


    Advisory IDSUSE-SU-2023:4619-1
    ReleasedThu Nov 30 10:13:52 2023
    SummarySecurity update for sqlite3
    Typesecurity
    Severityimportant
    References1210660,CVE-2023-2137
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2023:4671-1
    ReleasedWed Dec 6 14:33:41 2023
    SummaryRecommended update for man
    Typerecommended
    Severitymoderate
    References
    Description:


    This update of man fixes the following problem:


    Advisory IDSUSE-RU-2023:4700-1
    ReleasedMon Dec 11 07:03:27 2023
    SummaryRecommended update for p11-kit
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for p11-kit fixes the following issues:


    Advisory IDSUSE-RU-2023:4723-1
    ReleasedTue Dec 12 09:57:51 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1216862
    Description:

    This update for libtirpc fixes the following issue:


    Advisory IDSUSE-SU-2023:4891-1
    ReleasedMon Dec 18 16:31:49 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1201384,1218014,CVE-2023-50495
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2024:26-1
    ReleasedThu Jan 4 11:15:24 2024
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1214980
    Description:

    This update for mozilla-nss fixes the following issues:
    Mozilla NSS was updated to NSS 3.90.1


    Advisory IDSUSE-RU-2024:62-1
    ReleasedMon Jan 8 11:44:47 2024
    SummaryRecommended update for libxcrypt
    Typerecommended
    Severitymoderate
    References1215496
    Description:

    This update for libxcrypt fixes the following issues:


    Advisory IDSUSE-RU-2024:97-1
    ReleasedFri Jan 12 07:48:18 2024
    SummaryRecommended update for Java
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for Java fixes the following issues:
    apache-commons-daemon was updated from version 1.3.2 to 1.3.4:


    aqute-bnd was updated from version 5.2.0 to 6.3.1:
    tomcat-jakartaee-migration:
  • New package implementation of tomcat-jakartaee-migration at version 1.0.7

  • libtcnative-1-0 was updated from version 1.2.22 to 1.2.38:


    Advisory IDSUSE-SU-2024:136-1
    ReleasedThu Jan 18 09:53:47 2024
    SummarySecurity update for pam
    Typesecurity
    Severitymoderate
    References1217000,1218475,CVE-2024-22365
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-feature-2024:178-1
    ReleasedTue Jan 23 10:35:18 2024
    SummaryFeature update for tomcat10, jakarta-servlet, apache-commons-jexl
    Typefeature
    Severitymoderate
    References
    Description:

    This update for tomcat10, jakarta-servlet and apache-commons-jexl fixes the following issues:
    tomcat10:


    apache-commons-jexl:

    jakarta-servlet:


    Advisory IDSUSE-RU-2024:201-1
    ReleasedWed Jan 24 04:17:43 2024
    SummaryRecommended update for ecj
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for ecj fixes the following issues:


    Advisory IDSUSE-SU-2024:208-1
    ReleasedWed Jan 24 13:54:35 2024
    SummarySecurity update for tomcat10
    Typesecurity
    Severitymoderate
    References1217649,CVE-2023-46589
    Description:

    This update for tomcat10 fixes the following issues:
    Updated to Tomcat 10.1.18


    Find the full release notes at:
    https://tomcat.apache.org/tomcat-9.0-doc/changelog.html


    Advisory IDSUSE-SU-2024:473-1
    ReleasedWed Feb 14 15:02:43 2024
    SummarySecurity update for tomcat10
    Typesecurity
    Severityimportant
    References1219208,CVE-2024-22029
    Description:

    This update for tomcat10 fixes the following issues:


    Advisory IDSUSE-SU-2024:555-1
    ReleasedTue Feb 20 17:22:17 2024
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1219576,CVE-2024-25062
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2024:560-1
    ReleasedWed Feb 21 05:34:18 2024
    SummaryRecommended update for Java
    Typerecommended
    Severitymoderate
    References1215973,CVE-2023-37460
    Description:

    This update for Java fixes the following issues:
    plexus-archiver was updated from version 4.2.1 to 4.8.0:


    * Security issues fixed:
    + CVE-2023-37460: Avoid override target symlink by standard file in AbstractUnArchiver (bsc#1215973)
    * New features and improvements:
    + Added tzst alias for tar.zst archiver/unarchived
    * Bugs fixed:
    + Detect permissions for addFile
    * Maintenance:
    + Removed public modifier from JUnit 5 tests + Use https in scm/url + Removed junit-jupiter-engine from project dependencies + Removed parent and reports menu from site + Cleanup after 'veryLargeJar' test + Override project.url

    * Bugs fixed:
    + Don't apply umask on unknown perms (Win)

    * New features and improvements:
    + add umask support and use 022 in RB mode + Use NIO Files for creating temporary files + Deprecate the JAR Index feature (JDK-8302819) + Added Archiver aliases for tar.*
    * Maintenance:
    + Use JUnit TempDir to manage temporary files in tests + Override uId and gId for Tar in test + Bump maven-resources-plugin from 2.7 to 3.3.1

    * New features and improvements:
    + Fixed path traversal vulnerability The vulnerability affects only directories whose name begins with the same prefix as the destination directory. For example malicious archive may extract file in /opt/directory instead of /opt/dir.

    * Bugs fixed:
    + Fixed regression in handling symbolic links

    * Bugs fixed:
    + Normalize file separators before warning about equal archive entries

    * New features and improvements:
    + keep file/directory permissions in Reproducible Builds mode

    * New features and improvements:
    + Added zstd (un)archiver support
    * Bugs fixed:
    + Fixed UnArchiver#isOverwrite not working as expected

    * New features and improvements:
    + Drop legacy plexus API and use only JSR330 components

    * New features and improvements:
    + Require Java 8 + Refactor to use FileTime API + Rename setTime method to setZipEntryTime + Convert InputStreamSupplier to lambdas
    * Bugs fixed:
    + Reproducible Builds not working when using modular jar

    * New features and improvements:
    + Respect order of META-INF/ and META-INF/MANIFEST.MF entries in a JAR file

    * New features and improvements:
    + FileInputStream, FileOutputStream, FileReader and FileWriter are no longer used + Code cleanup

    * New features and improvements: + Speed improvements
    * Bugs fixed:
    + Fixed use of a mismatching Unicode path extra field in zip unarchiving

    * Bugs fixed:
    + Fixed unjustified warning about casing for directory entries

    * Bugs fixed:
    + DirectoryArchiver fails for symlinks if a parent directory doesn't exist
    objectweb-asm was updated to version 9.6:

    * New Opcodes.V22 constant for Java 22
    * Bugs fixed:
    + Analyzer produces frames that have different locals than those detected by JRE bytecode verifier + Invalid stackmap generated when the instruction stream has new instruction after invokespecial to + Analyzer can fail to catch thrown exceptions + `asm-analysis` Frame allocates an array unnecessarily inside `executeInvokeInsn` + Fixed bug in `CheckFrameAnalyzer` with static methods

    * New Opcodes.V21 constant for Java 21 * New readBytecodeInstructionOffset hook in ClassReader * Added more detailed exception messages * Javadoc improvements and fixes
    * Bugs fixed:
    + Silent removal of zero-valued entries from the line-number table

    * Changes:
    + New Opcodes.V20 constant for Java 20 + Added more checks in CheckClassAdapter + Javadoc improvements and fixes + `module-info` classes can be built without Gradle and Bnd + Parent POM updated to `org.ow2:ow2:1.5.1`
    * Bugs fixed:
    +`CheckClassAdapter` is no longer transparent for MAXLOCALS + Added public `getDelegate` method to all visitor classes + Analyzer does not compute optimal maxLocals for static methods + Fixed `SignatureWriter` when a generic type has a depth over 30 + Skip remap inner class name if not changed in Remapper
    maven-archiver was updated from version 3.5.0 to 3.6.1:

    * New Features:
    + Deprecated the JAR Index feature (JDK-8302819)
    * Task:
    + Refreshed download page + Prefer JDK features over plexus-utils, plexus-io

    * Task:
    + Require Java 8 + Drop m-shared-utils from deps
    maven-assembly-plugin was updated from version 3.3.0 to 3.6.0:

    * Bugs fixed:
    + finalName as readonly parameter makes common usecases very complicated + Symbolic links get copied with absolute path + Warning if using Maven 3.9.1 + Minimal default Manifest configuration of jar archiver should be respected
    * New Features:
    + Support Zstandard compression format
    * Improvements:
    + In RB mode, apply 022 umask to ignore environment group write umask + Added system requirements history
    * Task: + Dropped deprecated repository element + Support running build on Java 20 + Refresh download page + Cleanup declared dependencies + Avoid using deprecated methods of `plexus-archiver`

    * Bugs fixed:
    + File permissions removed during assembly:single since 3.2.0

    * Bugs fixed:
    + Fixed Excludes filtering
    * Task:
    + Fixed examples to refer to https instead of http

    * Bugs fixed:
    + Fixed error build with shared assemblies

    * Bugs fixed:
    + dependencySet includes filter with classifier breaks include of artifacts without classifier
    * Task:
    + Speed improvements + Update plugin (requires Maven 3.2.5+) + Assembly plugin resolves too much, even plugins used to build dependencies + Deprecated the repository element in assembly descriptor + Upgraded to Java 8, drop unused dependencies
    maven-common-artifact-filters was updated from version 3.0.1 to 3.3.2:

    * Bugs fixed:
    + PatternIncludesArtifactFilters raising NPE for patterns w/ wildcards and artifactoid w/ null on any coordinate

    * Bugs fixed:
    + Pattern w/ 4 elements may be GATV or GATC

    * Bugs fixed:
    + null passed to DependencyFilter in EclipseAetherFilterTransformerTest + PatternIncludesArtifactFilter#include(Artifact) + Common Artifact Filters pattern parsing with classifier is broken
    * Task:
    + Sanitized dependencies + Upgraded to Maven Parent 36, to Maven 3.2.5, to Java 8 and clean up dependencies

    * Improvements:
    + Big speed improvements for patterns that do not contain any wildcard

    * Bugs fixed:
    + Updated JIRA URL for maven-common-artifact-filters
    * Improvements:
    + Made build Reproducible

    * Bugs fixed:
    + Several filters do not preserve order of artifacts filtered
    maven-compiler-plugin was updated from version 3.10.1 to 3.11.0:
    Changes of 3.11.0:
    * New features and improvements:
    + Added a useModulePath switch to the testCompile mojo + Allow dependency exclusions for 'annotationProcessorPaths' + Use maven-resolver to resolve 'annotationProcessorPaths' dependencies + Upgrade plexus-compiler to improve compiling message + compileSourceRoots parameter should be writable + Change showWarnings to true by default + Warn about warn-config conflicting values + Update default source/target from 1.7 to 1.8 + Display recompilation causes + Added some parameter to pattern from stale source calculation + Added dedicated option for implicit javac flag
    * Bugs fixed:
    + Fixed incorrect detection of dependency change + Test with Maven 3.9.0 and fix the failing IT + Resolved all annotation processor dependencies together + Defining maven.compiler.release as empty string ends with NumberFormatException in testCompileMojo + Fixed missing dirs in createMissingPackageInfoClasses + Set Xcludes in config passed to actual compiler
    maven-dependency-analyzer was updated from version 1.10 to 1.13.2:

    * Changes and bugs fixed:
    + Made mvn dependency:analyze work with OpenJDK 11 + Fixed jdk8 incompatibility at runtime (NoSuchMethodError) + Upgraded asm to 8.0.1 + Use try with resources to avoid leaks + dependency:analyze recommends test scope for test-only artifacts that have non-test scope + remove reference to deprecated public mutable field + Updated JIRA URL + dependency:analyze should recommend narrower scope where possible + Remove dependency on jmock + Inline deprecated field + Added more JavaDoc + Handle different classes from same artifact used by model and test code + Included class names in used undeclared dependencies + Check maximum allowed Maven version + Get rid of maven-plugin-testing-tools for IT test + Require Maven 3.2.5+ + Analyze project classes only once + Fixed array parsing + CONSTANT_METHOD_TYPE should not add to classes + Inner classes are in same compilation unit as container class + Upgraded Parent to 36 + Cleanup IT tests + Replace Codehaus Plexus utils with java.nio.file.Files and Apache Commons + Fixed bug with 'non-test scoped test only dependencies found' + Bump asm from 9.4 to 9.5 + Refresh download page + Upgrade Parent to 39 + Build on JDK 19, 20 + Prefer JDK classes to Plexus utils + Replaced System.out by logger + Fixed java.lang.RuntimeException: Unknown constant pool type + Switched to JUnit 5 + Dependency improvements
    maven-dependency-plugin was updated from version 3.1.2 to 3.6.0:

    * Bugs fixed:
    + Obsolete example of -Dverbose on web page + Unsupported verbose option still appears in docs + dependency:go-offline does not use repositories from parent pom in reactor build + Fixed possible NPE + `dependency:analyze-only` goal fails on OpenJDK 14 + FileWriter and FileReader should be replaced + Dependency Plugin go-offline doesn't respect artifact classifier + analyze-only failed: Unsupported class file major version 60 (Java 16) + analyze-only failed: Unsupported class file major version 61 (Java 17) + copy-dependencies fails when using excludeScope=test + mvn dependency:analyze detected wrong transitive dependency + dependency plugin does not work with JDK 16 + skip dependency analyze in ear packaging + Non-test dependency reported as Non-test scoped test only dependency + 'Dependency not found' with 3.2.0 and Java-17 while analyzing + Tree plugin does not terminate with 3.2.0 + Minor improvement - continue + analyze-only failed: PermittedSubclasses requires ASM9 + Broken Link to 'Introduction to Dependency Mechanism Page' + Sealed classes not supported + Dependency tree in verbose mode for war is empty + Javadoc was not updated to reflect that :tree's verbose option is now ok + error dependency:list (caused by postgresql dependency) + :list-classes does not skip if skip is set + :list-classes does not use GAV parameters
    * New Features:
    + Reintroduce the verbose option for dependency:tree + List classes in a given artifact + dependency:analyze should recommend narrower scope where possible + Added analyze parameter 'ignoreUnusedRuntime' + Allow ignoring non-test-scoped dependencies + Added a option to unpack goals + Allow auto-ignore of all non-test scoped dependencies used only in test scope
    * Improvements:
    + Unused method o.a.m.p.d.t.TreeMojo.containsVersion + Minor improvements + GitHub Action build improvement + dependency:analyze should list the classes that cause a used undeclared dependency + Improve documentation of analyze - Non-test scoped + Turn warnings into errors instead of failOnWarning + maven-dependency-plugin should leverage plexus-build-api to support IDEs + TestListClassesMojo logs too much + Use outputDirectory from AbstractMavenReport + Removed not used dependencies / Replace parts + list-repositories - improvements + warns about depending on plexus-container-default + Replace AnalyzeReportView with a new AnalyzeReportRenderer
    * Task:
    + Removed no longer required exclusions + Java 1.8 as minimum + Explicitly start and end tables with Doxia Sinks in report renderers + Replace Maven shared StringUtils with Commons Lang3 + Removed unused and ignored parameter - useJvmChmod + Removed custom plexus configuration + Code refactor - UnpackUtil + Refresh download page
    maven-dependency-tree was updated from version 3.0.1 to 3.2.1:

    * Bugs fixed:
    + DependencyCollectorBuilder does not collect dependencies when artifact has 'war' packaging + Transitive provided dependencies are not removed from collected dependency graph
    * New Features:
    + DependencyCollectorBuilder more configurable
    * Improvements:
    + DependencyGraphBuilder does not provide verbose tree + DependencyGraphBuilders shouldn't need reactorProjects for resolving dependencies + Maven31DependencyGraphBuilder should not download dependencies other than the pom + Fixed `plexus-component-annotation` in line with `plexus-component-metadata` + Upgraded parent to 31 + Added functionality to collect raw dependencies in Maven 3+ + Annotate DependencyNodes with dependency management metadata + Require Java 8 + Upgrade `org.eclipse.aether:aether-util` dependency in org.apache.maven.shared:maven-dependency-tree + Added Exclusions to DependencyNode + Made build Reproducible + Migrate plexus component to JSR-330 + Drop maven 3.0 compatibility
    * Dependency upgrade:
    + Upgrade shared-component to version 33 + Upgrade Parent to 36 + Bump maven-shared-components from 36 to 37

    maven-enforcer was updated to version 3.4.1:

    * Bugs fixed:
    + In a multi module project 'bannedDependencies' rule tries to resolve project artifacts from external repository + Require Release Dependencies ignorant about aggregator build + banDuplicatePomDependencyVersions does not check managementDependencies + Beanshell rule is not thread-safe + RequireSnapshotVersion not compatible with CI Friendly Versions (${revision}) + NPE when using new syntax with maven-enforcer-plugin + Broken links on Maven Enforcer Plugin site + RequirePluginVersions not recognizing versions-from-properties + [REGRESSION] RequirePluginVersions fails when versions are inherited + requireFilesExist rule should be case sensitive + Broken Links on Project Home Page + TestRequireOS uses hamcrest via transitive dependency + plexus-container-default in enforcer-api is very outdated + classifier not included in output of failes RequireUpperBoundDeps test + Exclusions are not considered when looking at parent for requireReleaseDeps + requireUpperBoundDeps does not fail when packaging is 'war' + DependencyConvergence in 3.0.0 fails on provided scoped dependencies + NPE on requireReleaseDeps with non-matching includes + RequireUpperBoundDeps now follow scope provided transitive dependencies + Use currently build artifacts in IT tests + requireReleaseDeps does not support optional dependencies or runtime scope + Enforcer 3.0.0 breaks with Maven 3.8.4 + Version 3.1.0 is not enforcing bannedDependencies rules + DependencyConvergence treats provided dependencies are runtime dependencies + Plugin shouldn't use NullPointerException for non-exceptional code flow + NPE in RequirePluginVersions + ReactorModuleConvergence not cached in reactor + RequireUpperBoundDeps fails on provided dependencies since 3.2.1 + Problematic dependency resolution by new 'banDynamicVersions' rule + banTransitiveDependencies: failing if a transitive dependencies has another version than the resolved one + Filtering dependency tree by scope + Upgrading to 3.0.0 causes 'Could not build dependency tree' with repositories some unknown protocol + DependencyConvergence in 3.1.0 fails when using version ranges + Semantics of 'ignores' parameter of 'banDynamicVersions' is inverted + Omission of 'excludedScopes' parameter of 'banDynamicVersions' causes NPE + ENFORCER: plugin-info and mojo pages not found
    * New Features:
    + requireUpperBounds deps should have includes + Introduce RequireTextFileChecksum with line separator normalization + allow no rules + show rules processed + DependencyConvergence should support including/excluding certain dependencies + Support declaring external banned dependencies in an external file/URL + Maven enforcer rule which checks that all dependencies have an explicit scope set + Maven enforcer rule which checks that all dependencies in dependencyManagement don't have an explicit scope set + Rule for no version ranges, version placeholders or SNAPSHOT versions + Allow one of many files in RequireFiles rules to pass + Skip specific rules + New Enforcer API + New Enforcer API - RuleConfigProvider + Move Built-In Rules to new API
    * Improvements:
    + wildcard ignore in requireReleaseDeps + Improve documentation about writing own Enforcer Rule + RequireActiveProfile should respect inherited activated profiles + Upgrade maven-dependency-tree to 3.x + Improve dependency resolving in multiple modules project + requireUpperBoundDeps: add [] and colors to the output + Example for writing a custom rule should be upgraded + Along with JavaVersion, allow enforcement of the JavaVendor + Included Java vendor in display-info output + requireMavenVersion x.y.z is processed as (,x.y.z] instead of [x.y.z,) + Consistently format artifacts same as dependency:tree + Made build Reproducible + Added support for excludes/includes in requireJavaVendor rule + Introduce Maven Enforcer Extension + Extends RequirePluginVersions with banMavenDefaults + Shared GitHub Actions + Log at ERROR level when is set + Reuse getDependenciesToCheck results across rules + Violation messages can be really hard to find in a multi module project + Clarify class loading for custom Enforcer rules + Using junit jupiter bom instead of single artifacts. + Get rid of maven-dependency-tree dependency + Allow 8 as JDK version for requireJavaVersion + Improve error message for rule 'requireJavaVersion' + Include Java Home in Message for Java Rule Failures + Manage all Maven Core dependencies as provided + Mange rules configuration by plugin + Deprecate 'rules' property and introduce 'enforcer.rules' as a replacement + Change success message from executed to passed + EnforcerLogger: Provide isDebugEnabled(), isErrorEnabled(), isWarnEnabled() and isInfoEnabled() + Properly declare dependencies
    * Test:
    + Regression test for dependency convergence problem fixed in 3.0.0
    * Task:
    + Removed reference to travis or switch to travis.com + Fixed maven assembly links + Require Java 8 + Verify working with Maven 4 + Code cleanup + Refresh download page + Deprecate display-info mojo + Refresh site descriptors + Superfluous blanks in BanDuplicatePomDependencyVersions + Rename ResolveUtil to ResolverUtil
    maven-plugin-tools was updated from version 3.6.0 to version 3.9.0:
    - Changes of version 3.9.0:
    * Bugs fixed:
    + Fixed *-mojo.xml (in PluginXdocGenerator) is overwritten when multiple locales are defined + Generated table by PluginXdocGenerator does not contain default attributes
    * Improvements:
    + Omit empty line in generated help goal output if plugin description is empty + Use Plexus I18N rather than fiddling with
    * Task:
    + Removed reporting from maven-plugin-plugin: create maven-plugin-report-plugin
    * Dependency upgrade:
    + Upgrade plugins and components (in ITs)
    • Changes of version 3.8.2:

    * Improvements:
    + Used Resolver API, get rid of localRepository
    * Dependency upgrade:
    + Bump httpcore from 4.4.15 to 4.4.16 + Bump httpclient from 4.5.13 to 4.5.14 + Bump antVersion from 1.10.12 to 1.10.13 + Bump slf4jVersion from 1.7.5 to 1.7.36 + Bump plexus-java from 1.1.1 to 1.1.2 + Bump plexus-archiver from 4.6.1 to 4.6.3 + Bump jsoup from 1.15.3 to 1.15.4 + Bump asmVersion from 9.4 to 9.5 + Bump assertj-core from 3.23.1 to 3.24.2
    • Changes of version 3.8.1:

    * Bugs fixed:
    + Javadoc reference containing a link label with spaces are not detected + JavadocLinkGenerator.createLink: Support nested binary class names + ERROR during build of m-plugin-report-p and m-plugin-p: Dependencies in wrong scope + 'Executes as an aggregator plugin' documentation: s/plugin/goal/ + Maven scope warning should be logged at WARN level + Fixed Temporary File Information Disclosure Vulnerability
    * New features:
    + Support mojos using the new maven v4 api
    * Improvements:
    + Plugin descriptor should contain the requiredJavaVersion/requiredMavenVersion + Execute annotation only supports standard lifecycle phases due to use of enum + Clarify deprecation of all extractors but the maven-plugin-tools-annotations
    * Dependency upgrade:
    + Update to Maven Parent POM 39 + Bump junit-bom from 5.9.1 to 5.9.2 + Bump plexus-archiver from 4.5.0 to 4.6.1
    • Changes of version 3.7.1: * Bugs fixed:

    + Maven scope warning should be logged at WARN level
    • Changes of version 3.7.0:

    * Bugs fixed:
    + The plugin descriptor generated by plugin:descriptor does not consider @ see javadoc taglets + Report-Mojo doesn't respect input encoding + Generating site reports for plugin results in NoSuchMethodError + JDK Requirements in plugin-info.html: Consider property 'maven.compiler.release' + Parameters documentation inheriting @ since from Mojo can be confusing + Don't emit warning for missing javadoc URL of primitives + Don't emit warning for missing javadoc URI if no javadoc sources are configured + Parameter description should be taken from annotated item
    * New Features:
    + Added link to javadoc in configuration description page for user defined types of Mojos. + Allow only @ Deprecated annotation without @ deprecated javadoc tag + add system requirements history section + report: allow to generate usage section in plugin-info.html with true + Allow @ Parameter on setters methods + Extract plugin report into its own plugin + report: Expose generics information of Collection and Map types
    * Improvement:
    + plugin-info.html should contain a better Usage section + Do not overwrite generate files with no content change + Upgrade to JUnit 5 and @ Inject annotations + Support for java 20 - ASM 9.4 + Don't print empty Memory, Disk Space in System Requirements + simplification in helpmojo build + Get rid of plexus-compiler-manager from tests + Use Maven core artifacts in provided scope + report and descriptor goal need to evaluate Javadoc comments differently + Allow to reference aggregator javadoc from plugin report
    * Task:
    + Detect legacy/javadoc Mojo definitions, warn to use Java 5 annotations + Update level to Java 8 + Deprecate scripting support for mojos + Deprecate requirements parameter in report Mojo + Removed duplicate code from PluginReport + Prepare for Doxia (Sitetools) 2.0.0 + Fixed documentation for maven-plugin-report-plugin + Removed deprecated items from new maven-plugin-report-plugin + Improve site build + Improve dependency management + Plugin generator generation fails when the parent class comes from a different project
    * Dependency upgrade:
    + Upgrade Maven Reporting API/Impl to 3.1.0 + Upgrade Parent to 36 + Upgrade project dependencies after JDK 1.8 + Bump maven-parent from 36 to 37 + Upgrade Maven Reporting API to 3.1.1/Maven Reporting Impl to 3.2.0 + Upgrade plexus-utils to 3.5.0
    • Changes of version 3.6.4:

    * Restored compatibility with Maven 3 ecosystem * Upgraded dependencies
    • Changes of version 3.6.3:

    * Added prerequisites to plugin pom * Exclude dependency in provided scope from plugin descriptor * Get rid of String.format use * Fixed this logging as well * Simplify documentation * Exclude maven-archiver and maven-jxr from warning
    • Changes of version 3.6.2:

    * Deprecated unused requiresReports flag * Check that Maven dependencies are provided scope * Update ITs * Use shared gh action * Deprecate unsupported Mojo descriptor items * Weed out ITs * Upgrade to maven 3.x and avoid using deprecated API * Drop legacy dependencies * Use shared gh action - v1 * Fixed wording in javadoc
    • Changes of version 3.6.1:

    * What's Changed: * Added missing @OverRide and make methods static * Upgraded to JUnit 4.12 * Upgraded parent POM and other dependencies * Updated plugins * Upgraded Doxia Sitetools to 1.9.2 to remove dependency on Struts * removed Maven 2 info * Removed unneeded dependency * Tighten the dependency tree * Ignore .checkstyle * Strict dependencies for maven-plugin-tools-annotations * Improved @execute(goal...) docs * Improve @execute(lifecycle...) docs
    plexus-compiler was updated from version 2.11.1 to 2.14.2:
    • Changes of 2.14.2:

    * Removed:
    + Drop J2ObjC compiler
    * New features and improvements:
    + Update AspectJ Compiler to 1.9.21 to support Java 21 + Require JDK 17 for build + Improve locking on JavacCompiler + Include 'parameter' and 'preview' describe log + Switch to SISU annotations and plugin, fixes #217 + Support jdk 21 + Require Maven 3.5.4+ + Require Java 11 for plexus-compiler-eclipse an javac-errorprone and aspectj compilers + Added support to run its with Java 20
    * Bugs fixed:
    + Fixed javac memory leak + Validate zip file names before extracting (Zip Slip) + Restore AbstractCompiler#getLogger() method + Return empty list for not existing source root location + Improve javac error output parsing
    • Changes of 2.13.0:

    * New features and improvements:
    + Fully ignore any possible jdk bug + MCOMPILER-402: Added implicitOption to CompilerConfiguration + Added a custom compile argument replaceProcessorPathWithProcessorModulePath to force the plugin replace processorPath with processormodulepath + describe compiler configuration on run + simplify 'Compiling' info message: display relative path
    * Bugs fixed:
    + Respect CompilerConfiguration.sourceFiles in EclipseJavaCompiler + Avoid NPE in AspectJCompilerTest on AspectJ 1.9.8+
    * Dependency updates:
    + Bump maven-surefire-plugin from 3.0.0-M5 to 3.0.0-M6 + Bump error_prone_core from 2.11.0 to 2.13.1 + Bump github/codeql-action from 1 to 2 + Bump ecj from 3.28.0 to 3.29.0 + Bump release-drafter/release-drafter from 5.18.1 to 5.19.0 + Bump ecj from 3.29.0 to 3.30.0 + Bump maven-invoker-plugin from 3.2.2 to 3.3.0 + Bump maven-enforcer-plugin from 3.0.0 to 3.1.0 + Bump error_prone_core from 2.13.1 to 2.14.0 + Bump maven-surefire-plugin from 3.0.0-M6 to 3.0.0-M7 + Bump ecj from 3.31.0 to 3.32.0 + Bump junit-bom from 5.9.0 to 5.9.1 + Bump ecj from 3.30.0 to 3.31.0 + Bump groovy from 3.0.12 to 3.0.13 + Bump groovy-json from 3.0.12 to 3.0.13 + Bump groovy-xml from 3.0.12 to 3.0.13 + Bump animal-sniffer-maven-plugin from 1.21 to 1.22 + Bump error_prone_core from 2.14.0 to 2.15.0 + Bump junit-bom from 5.8.2 to 5.9.0 + Bump groovy-xml from 3.0.11 to 3.0.12 + Bump groovy-json from 3.0.11 to 3.0.12 + Bump groovy from 3.0.11 to 3.0.12
    * Maintenance:
    + Require Maven 3.2.5


    Advisory IDSUSE-SU-2024:597-1
    ReleasedThu Feb 22 20:07:11 2024
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1216198,CVE-2023-5388
    Description:

    This update for mozilla-nss fixes the following issues:
    Update to NSS 3.90.2:

    • CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198)


    Advisory IDSUSE-RU-2024:626-1
    ReleasedTue Feb 27 04:00:13 2024
    SummaryRecommended update for ecj
    Typerecommended
    Severityimportant
    References1219862
    Description:

    This update for ecj fixes the following issues:

    • Allow building ecj with language levels 8 (bsc#1219862)
    • Distribute the bundled javax17api.jar under maven coordinate of org.eclipse:javax17api:17, so that it can be used if needed


    Advisory IDSUSE-SU-2024:786-1
    ReleasedWed Mar 6 21:07:20 2024
    SummarySecurity update for giflib
    Typesecurity
    Severityimportant
    References1198880,1200551,1217390,CVE-2021-40633,CVE-2022-28506,CVE-2023-48161
    Description:

    This update for giflib fixes the following issues:
    Update to version 5.2.2

    • Fixes for CVE-2023-48161 (bsc#1217390), CVE-2022-28506 (bsc#1198880)
    • #138 Documentation for obsolete utilities still installed
    • #139: Typo in 'LZW image data' page ('110_2 = 4_10')
    • #140: Typo in 'LZW image data' page ('LWZ')
    • #141: Typo in 'Bits and bytes' page ('filed')
    • Note as already fixed SF issue #143: cannot compile under mingw
    • #144: giflib-5.2.1 cannot be build on windows and other platforms using c89
    • #145: Remove manual pages installation for binaries that are not installed too
    • #146: [PATCH] Limit installed man pages to binaries, move giflib to section 7
    • #147 [PATCH] Fixes to doc/whatsinagif/ content
    • #148: heap Out of Bound Read in gif2rgb.c:298 DumpScreen2RGB
    • Declared no-info on SF issue #150: There is a denial of service vulnerability in GIFLIB 5.2.1
    • Declared Won't-fix on SF issue 149: Out of source builds no longer possible
    • #151: A heap-buffer-overflow in gif2rgb.c:294:45
    • #152: Fix some typos on the html documentation and man pages
    • #153: Fix segmentation faults due to non correct checking for args
    • #154: Recover the giffilter manual page
    • #155: Add gifsponge docs
    • #157: An OutofMemory-Exception or Memory Leak in gif2rgb
    • #158: There is a null pointer problem in gif2rgb
    • #159 A heap-buffer-overflow in GIFLIB5.2.1 DumpScreen2RGB() in gif2rgb.c:298:45
    • #163: detected memory leaks in openbsd_reallocarray giflib/openbsd-reallocarray.c
    • #164: detected memory leaks in GifMakeMapObject giflib/gifalloc.c
    • #166: a read zero page leads segment fault in getarg.c and memory leaks in gif2rgb.c and gifmalloc.c
    • #167: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function at Line 321 of gif2rgb.c


    Advisory IDSUSE-RU-2024:826-1
    ReleasedMon Mar 11 03:54:41 2024
    SummaryRecommended update for tomcat10
    Typerecommended
    Severitymoderate
    References1219530
    Description:

    This update for tomcat10 fixes the following issues:

    • Added dependencies on tomcat `user` and `group`, required by RPM 4.19 (bsc#1219530)
    • Link ecj.jar into the install instead of copying it


    Advisory IDSUSE-RU-2024:907-1
    ReleasedFri Mar 15 08:57:38 2024
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1215377
    Description:

    This update for audit fixes the following issue:

    • Fix plugin termination when using systemd service units (bsc#1215377)


    Advisory IDSUSE-RU-2024:929-1
    ReleasedTue Mar 19 06:36:24 2024
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1219321
    Description:

    This update for coreutils fixes the following issues:

    • tail: fix tailing sysfs files where PAGE_SIZE > BUFSIZ (bsc#1219321)


    Advisory IDSUSE-RU-2024:1112-1
    ReleasedThu Apr 4 14:29:36 2024
    SummaryRecommended update for tomcat10
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for tomcat10 fixes the following issues:

    • Add missing Requires(post): util-linux to have runuser into post
    • Add %%systemd_ordering to packages with systemd unit files, so that the order is the right one if those packages
    find themselves in the same transaction with systemd


    Advisory IDSUSE-SU-2024:1129-1
    ReleasedMon Apr 8 09:12:08 2024
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1219559,1221289,CVE-2023-52425,CVE-2024-28757
    Description:

    This update for expat fixes the following issues:

    • CVE-2023-52425: Fixed a DoS caused by processing large tokens. (bsc#1219559)
    • CVE-2024-28757: Fixed an XML Entity Expansion. (bsc#1221289)


    Advisory IDSUSE-SU-2024:1133-1
    ReleasedMon Apr 8 11:29:02 2024
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1220061,CVE-2023-45918
    Description:

    This update for ncurses fixes the following issues:

    • CVE-2023-45918: Fixed NULL pointer dereference via corrupted xterm-256color file (bsc#1220061).


    Advisory IDSUSE-SU-2024:1204-1
    ReleasedThu Apr 11 12:43:41 2024
    SummarySecurity update for tomcat10
    Typesecurity
    Severityimportant
    References1221385,1221386,CVE-2024-23672,CVE-2024-24549
    Description:

    This update for tomcat10 fixes the following issues:

    • CVE-2024-24549: Fixed denial of service during header validation for HTTP/2 stream (bsc#1221386)
    • CVE-2024-23672: Fixed denial of service due to malicious WebSocket client keeping connection open (bsc#1221385)

    Other fixes:
    • Update to Tomcat 10.1.20 * Catalina + Fix: Minor performance improvement for building filter chains. Based on ideas from #702 by Luke Miao. (remm) + Fix: Align error handling for Writer and OutputStream. Ensure use of either once the response has been recycled triggers a NullPointerException provided that discardFacades is configured with the default value of true. (markt) + Fix: 68692: The standard thread pool implementations that are configured using the Executor element now implement ExecutorService for better support NIO2. (remm) + Fix: 68495: When restoring a saved POST request after a successful FORM authentication, ensure that neither the URI, the query string nor the protocol are corrupted when restoring the request body. (markt) + Fix: After forwarding a request, attempt to unwrap the response in order to suspend it, instead of simply closing it if it was wrapped. Add a new suspendWrappedResponseAfterForward boolean attribute on Context to control the bahavior, defaulting to false. (remm) + Fix: 68721: Workaround a possible cause of duplicate class definitions when using ClassFileTransformers and the transformation of a class also triggers the loading of the same class. (markt) + Fix: The rewrite valve should not do a rewrite if the output is identical to the input. (remm) + Update: Add a new valveSkip (or VS) rule flag to the rewrite valve to allow skipping over the next valve in the Catalina pipeline. (remm) + Update: Add highConcurrencyStatus attribute to the SemaphoreValve to optionally allow the valve to return an error status code to the client when a permit cannot be acquired from the semaphore. (remm) + Add: Add checking of the 'age' of the running Tomcat instance since its build-date to the SecurityListener, and log a warning if the server is old. (schultz) + Fix: When using the AsyncContext, throw an IllegalStateException, rather than allowing an NullPointerException, if an attempt is made to use the AsyncContext after it has been recycled. (markt) + Fix: Correct JPMS and OSGi meta-data for tomcat-embed-core.jar by removing reference to org.apache.catalina.ssi package that is no longer included in the JAR. Based on pull request #684 by Jendrik Johannes. (markt) + Fix: Fix ServiceBindingPropertySource so that trailing \r\n sequences are correctly removed from files containing property values when configured to do so. Bug identified by Coverity Scan. (markt) + Add: Add improvements to the CSRF prevention filter including the ability to skip adding nonces for resource name and subtree URL patterns. (schultz) + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. (remm) + Fix: 68089: Further improve the performance of request attribute access for ApplicationHttpRequest and ApplicationRequest. (markt) + Fix: 68559: Allow asynchronous error handling to write to the response after an error during asynchronous processing. (markt) * Coyote + Fix: Improve the HTTP/2 stream prioritisation process. If a stream uses all of the connection windows and still has content to write, it will now be added to the backlog immediately rather than waiting until the write attempt for the remaining content. (markt) + Fix: Add threadsMaxIdleTime attribute to the endpoint, to allow configuring the amount of time before an internal executor will scale back to the configured minSpareThreads size. (remm) + Fix: Correct a regression in the support for user provided SSLContext instances that broke the org.apache.catalina.security.TLSCertificateReloadListener. (markt) + Fix: Setting a null value for a cookie attribute should remove the attribute. (markt) + Fix: Make asynchronous error handling more robust. Ensure that once a connection is marked to be closed, further asynchronous processing cannot change that. (markt) + Fix: Make asynchronous error handling more robust. Ensure that once the call to AsyncListener.onError() has returned to the container, only container threads can access the AsyncContext. This protects against various race conditions that woudl otherwise occur if application threads continued to access the AsyncContext. + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. In particular, most of the HTTP/2 debug logging has been changed to trace level. (remm) + Fix: Add support for user provided SSLContext instances configured on SSLHostConfigCertificate instances. Based on pull request #673 provided by Hakan Altındağ. (markt) + Fix: Partial fix for 68558: Cache the result of converting to String for request URI, HTTP header names and the request Content-Type value to improve performance by reducing repeated byte[] to String conversions. (markt) + Fix: Improve error reporting to HTTP/2 clients for header processing errors by reporting problems at the end of the frame where the error was detected rather than at the end of the headers. (markt) + Fix: Remove the remaining reference to a stream once the stream has been recycled. This makes the stream eligible for garbage collection earlier and thereby improves scalability. (markt) * Jasper + Add: Add support for specifying Java 22 (with the value 22) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will used. (markt) + Fix: Handle the case where the JSP engine forwards a request/response to a Servlet that uses an OutputStream rather than a Writer. This was triggering an IllegalStateException on code paths where there was a subsequent attempt to obtain a Writer. (markt) + Fix: Correctly handle the case where a tag library is packaged in a JAR file and the web application is deployed as a WAR file rather than an unpacked directory. (markt) + Fix: 68546: Generate optimal size and types for JSP imports maps, as suggested by John Engebretson. (remm) + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. (remm) * Cluster + Fix: Avoid updating request count stats on async. (remm) * WebSocket + Fix: Correct a regression in the fix for 66508 that could cause an UpgradeProcessor leak in some circumstances. (markt) + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. (remm) + Fix: Ensure that WebSocket connection closure completes if the connection is closed when the server side has used the proprietary suspend/resume feature to suspend the connection. (markt) * Web applications Add: Add support for responses in JSON format from the examples application RequestHeaderExample. (schultz) * Other + Add: Improvements to French translations. (remm) + Add: Improvements to Japanese translations by tak7iji. (markt) + Fix: 57130: Allow digest.(sh|bat) to accept password from a file or stdin. (csutherl/schultz) + Update: Update Checkstyle to 10.14.1. (markt) + Fix: Correct the remaining OSGi contract references in the manifest files to refer to the Jakarta EE contract names rather than the Java EE contract names. Based on pull request #685 provided by Paul A. Nicolucci. (markt) + Update: Update Checkstyle to 10.13.0. (markt) + Update: Update JSign to 6.0. (markt) + Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.7. (markt) + Update: Update Tomcat Native to 2.0.7. (markt) + Update: Add strings for debug level messages. (remm) + Add: Improvements to French translations. (remm) + Add: Improvements to Japanese translations by tak7iji. (markt)


    Advisory IDSUSE-RU-2024:1253-1
    ReleasedFri Apr 12 08:15:18 2024
    SummaryRecommended update for gcc13
    Typerecommended
    Severitymoderate
    References1210959,1214934,1217450,1217667,1218492,1219031,1219520,1220724,1221239
    Description:

    This update for gcc13 fixes the following issues:

    • Fix unwinding for JIT code. [bsc#1221239]
    • Revert libgccjit dependency change. [bsc#1220724]
    • Remove crypt and crypt_r interceptors. The crypt API change in SLE15 SP3 breaks them. [bsc#1219520]
    • Add support for -fmin-function-alignment. [bsc#1214934]
    • Use %{_target_cpu} to determine host and build.
    • Fix for building TVM. [bsc#1218492]
    • Add cross-X-newlib-devel requires to newlib cross compilers. [bsc#1219031]
    • Package m2rte.so plugin in the gcc13-m2 sub-package rather than in gcc13-devel. [bsc#1210959]
    • Require libstdc++6-devel-gcc13 from gcc13-m2 as m2 programs are linked against libstdc++6.
    • Fixed building mariadb on i686. [bsc#1217667]
    • Avoid update-alternatives dependency for accelerator crosses.
    • Package tool links to llvm in cross-amdgcn-gcc13 rather than in cross-amdgcn-newlib13-devel since that also has the dependence.
    • Depend on llvmVER instead of llvm with VER equal to %product_libs_llvm_ver where available and adjust tool discovery accordingly. This should also properly trigger re-builds when the patchlevel version of llvmVER changes, possibly changing the binary names we link to. [bsc#1217450]


    Advisory IDSUSE-SU-2024:1345-1
    ReleasedThu Apr 18 19:15:51 2024
    SummarySecurity update for tomcat
    Typesecurity
    Severityimportant
    References1221385,1221386,CVE-2024-23672,CVE-2024-24549
    Description:

    This update for tomcat fixes the following issues:

    • CVE-2024-24549: Fixed denial of service during header validation for HTTP/2 stream (bsc#1221386)
    • CVE-2024-23672: Fixed denial of service due to malicious WebSocket client keeping connection open (bsc#1221385)

    Other fixes:
    • Update to Tomcat 9.0.87 * Catalina + Fix: Minor performance improvement for building filter chains. Based on ideas from #702 by Luke Miao. (remm) + Fix: Align error handling for Writer and OutputStream. Ensure use of either once the response has been recycled triggers a NullPointerException provided that discardFacades is configured with the default value of true. (markt) + Fix: 68692: The standard thread pool implementations that are configured using the Executor element now implement ExecutorService for better support NIO2. (remm) + Fix: 68495: When restoring a saved POST request after a successful FORM authentication, ensure that neither the URI, the query string nor the protocol are corrupted when restoring the request body. (markt) + Fix: 68721: Workaround a possible cause of duplicate class definitions when using ClassFileTransformers and the transformation of a class also triggers the loading of the same class. (markt) + Fix: The rewrite valve should not do a rewrite if the output is identical to the input. (remm) + Update: Add a new valveSkip (or VS) rule flag to the rewrite valve to allow skipping over the next valve in the Catalina pipeline. (remm) + Fix: Correct JPMS and OSGi meta-data for tomcat-enbed-core.jar by removing reference to org.apache.catalina.ssi package that is no longer included in the JAR. Based on pull request #684 by Jendrik Johannes. (markt) + Fix: Fix ServiceBindingPropertySource so that trailing \r\n sequences are correctly removed from files containing property values when configured to do so. Bug identified by Coverity Scan. (markt) + Add: Add improvements to the CSRF prevention filter including the ability to skip adding nonces for resource name and subtree URL patterns. (schultz) + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. (remm) + Fix: 68089: Further improve the performance of request attribute access for ApplicationHttpRequest and ApplicationRequest. (markt) + Fix: 68559: Allow asynchronous error handling to write to the response after an error during asynchronous processing. (markt) * Coyote + Fix: Improve the HTTP/2 stream prioritisation process. If a stream uses all of the connection windows and still has content to write, it will now be added to the backlog immediately rather than waiting until the write attempt for the remaining content. (markt) + Fix: Make asynchronous error handling more robust. Ensure that once a connection is marked to be closed, further asynchronous processing cannot change that. (markt) + Fix: Make asynchronous error handling more robust. Ensure that once the call to AsyncListener.onError() has returned to the container, only container threads can access the AsyncContext. This protects against various race conditions that woudl otherwise occur if application threads continued to access the AsyncContext. + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. In particular, most of the HTTP/2 debug logging has been changed to trace level. (remm) + Fix: Add support for user provided SSLContext instances configured on SSLHostConfigCertificate instances. Based on pull request #673 provided by Hakan Altındağ. (markt) + Fix: Improve the Tomcat Native shutdown process to reduce the likelihood of a JVM crash during Tomcat shutdown. (markt) + Fix: Partial fix for 68558: Cache the result of converting to String for request URI, HTTP header names and the request Content-Type value to improve performance by reducing repeated byte[] to String conversions. (markt) + Fix: Improve error reporting to HTTP/2 clients for header processing errors by reporting problems at the end of the frame where the error was detected rather than at the end of the headers. (markt) + Fix: Remove the remaining reference to a stream once the stream has been recycled. This makes the stream eligible for garbage collection earlier and thereby improves scalability. (markt) * Jasper + Add: Add support for specifying Java 22 (with the value 22) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will used. (markt) + Fix: 68546: Generate optimal size and types for JSP imports maps, as suggested by John Engebretson. (remm) + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. (remm) * Cluster + Fix: Avoid updating request count stats on async. (remm) * WebSocket + Fix: Correct a regression in the fix for 66508 that could cause an UpgradeProcessor leak in some circumstances. (markt) + Fix: Review usage of debug logging and downgrade trace or data dumping operations from debug level to trace. (remm) + Fix: Ensure that WebSocket connection closure completes if the connection is closed when the server side has used the proprietary suspend/resume feature to suspend the connection. (markt) * Web applications + Add: Add support for responses in JSON format from the examples application RequestHeaderExample. (schultz) * Other + Add: Improvements to French translations. (remm) + Add: Improvements to Japanese translations by tak7iji. (markt) + Update: Update Checkstyle to 10.13.0. (markt) + Update: Update JSign to 6.0. (markt) + Update: Add strings for debug level messages. (remm) + Update: Update Tomcat Native to 1.3.0. (markt) + Add: Improvements to French translations. (remm) + Add: Improvements to Japanese translations by tak7iji. (markt)


    Advisory IDSUSE-RU-2024:1429-1
    ReleasedWed Apr 24 15:13:10 2024
    SummaryRecommended update for ca-certificates
    Typerecommended
    Severitymoderate
    References1188500,1221184
    Description:

    This update for ca-certificates fixes the following issue:

    • Update version (bsc#1221184) * Use flock to serialize calls (bsc#1188500) * Make certbundle.run container friendly * Create /var/lib/ca-certificates if needed


    Advisory IDSUSE-RU-2024:1665-1
    ReleasedThu May 16 08:00:09 2024
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1221632
    Description:

    This update for coreutils fixes the following issues:

    • ls: avoid triggering automounts (bsc#1221632)


    Advisory IDSUSE-SU-2024:1874-1
    ReleasedFri May 31 05:05:25 2024
    SummarySecurity update for Java
    Typesecurity
    Severityimportant
    References1187446,1224410,CVE-2021-33813
    Description:

    This update for Java fixes thefollowing issues:
    apiguardian was updated to vesion 1.1.2:

    • Added LICENSE/NOTICE to the generated jar
    • Allow @API to be declared at the package level
    • Explain usage of Status.DEPRECATED
    • Include OSGi metadata in manifest

    assertj-core was implemented at version 3.25.3:
    • New package implementation needed by Junit5

    byte-buddy was updated to version v1.14.16:
    • `byte-buddy` is required by `assertj-core`
    • Changes in version v1.14.16:

    * Update ASM and introduce support for Java 23.
    • Changes in version v1.14.15:

    * Allow attaching from root on J9.
    • Changes of v1.14.14:

    * Adjust type validation to accept additional names that are legal in the class file format. * Fix dynamic attach on Windows when a service user is active. * Avoid failure when using Android's strict mode.
    dom4j was updated to version 2.1.4:
    • Improvements and potentially breaking changes:

    * Added new factory method org.dom4j.io.SAXReader.createDefault(). It has more secure defaults than new SAXReader(), which uses system XMLReaderFactory.createXMLReader() or SAXParserFactory.newInstance().newSAXParser(). * If you use some optional dependency of dom4j (for example Jaxen, xsdlib etc.), you need to specify an explicit dependency on it in your project. They are no longer marked as a mandatory transitive dependency by dom4j. * Following SAX parser features are disabled by default in DocumentHelper.parse() for security reasons (they were enabled in previous versions): + http://xml.org/sax/properties/external-general-entities + http://xml.org/sax/properties/external-parameter-entities
    • Other changes:

    * Do not depend on jtidy, since it is not used during build * Fixed license to Plexus * JPMS: Add the Automatic-Module-Name attribute to the manifest. * Make a separate flavour for a minimal `dom4j-bootstrap` package used to build `jaxen` and full `dom4j` * Updated pull-parser version * Reuse the writeAttribute method in writeAttributes * Support build on OS with non-UTF8 as default charset * Gradle: add an automatic module name * Use Correct License Name 'Plexus' * Possible vulnerability of DocumentHelper.parseText() to XML injection * CVS directories left in the source tree * XMLWriter does not escape supplementary unicode characters correctly * writer.writeOpen(x) doesn't write namespaces * Fixed concurrency problem with QNameCache * All dependencies are optional * SAXReader: hardcoded namespace features * Validate QNames * StringIndexOutOfBoundsException in XMLWriter.writeElementContent() * TreeNode has grown some generics * QName serialization fix * DocumentException initialize with nested exception * Accidentally occurring error in a multi-threaded test * Added compatibility with W3C DOM Level 3 * Use Java generics
    hamcrest:
    • `hamcrest-core` has been replaced by `hamcrest` (no source changes)

    junit had the following change:
    • Require hamcrest >= 2.2

    junit5 was updated to version 5.10.2:
    • Conditional execution based on OS architectures
    • Configurable cleanup mode for @TempDir
    • Configurable thread mode for @Timeout
    • Custom class loader support for class/method selectors, @MethodSource, @EnabledIf, and @DisabledIf
    • Dry-run mode for test execution
    • Failure threshold for @RepeatedTest
    • Fixed build with the latest open-test-reporting milestone
    • Fixed dependencies in module-info.java files
    • Fixed unreported exception error that is fatal with JDK 21
    • Improved configurability of parallel execution
    • New @SelectMethod support in test @Suite classes.
    • New ConsoleLauncher subcommand for test discovery without execution
    • New convenience base classes for implementing ArgumentsProvider and ArgumentConverter
    • New IterationSelector
    • New LauncherInterceptor SPI
    • New NamespacedHierarchicalStore for use in third-party test engines
    • New TempDirFactory SPI for customizing how temporary directories are created
    • New testfeed details mode for ConsoleLauncher
    • New TestInstancePreConstructCallback extension API
    • Numerous bug fixes and minor improvements
    • Parameter injection for @MethodSource methods
    • Promotion of various experimental APIs to stable
    • Reusable parameter resolution for custom extension methods via ExecutableInvoker
    • Stacktrace pruning to hide internal JUnit calls
    • The binaries are compatible with java 1.8
    • Various improvements to ConsoleLauncher
    • XML reports in new Open Test Reporting format

    jdom:
    • Security issues fixed:

    * CVE-2021-33813: Fixed an XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request (bsc#1187446)
    • Other changes and bugs fixed: * Fixed wrong entries in changelog (bsc#1224410) * The packages `jaxen`, `saxpath` and `xom` are now separate standalone packages instead of being part of `jdom`

    jaxen was implemented at version 2.0.0:
    • New standalone RPM package implementation, originally part of `jdom` source package
    • Classpaths are much smaller and less complex, and will suppress a lot of noise from static analysis tools.
    • The Jaxen core code is also a little smaller and has fixed a few minor bugs in XPath evaluation
    • Despite the major version bump, this should be a drop in replacement for almost every project. The two major possible incompatibilities are: * The minimum supported Java version is now 1.5, up from 1.4 in 1.2.0 and 1.3 in 1.1.6. * dom4j, XOM, and JDOM are now optional dependencies so if a project was depending on them to be loaded transitively it will need to add explicit dependencies to build.

    jopt-simple:
    • Included jopt-simple to Package Hub 15 SP5 (no source changes)

    objectweb-asm was updated to version 9.7:
    • New Opcodes.V23 constant for Java 23
    • Bugs fixed * Fixed unit test regression in dex2jar. * Fixed 'ClassNode#outerClass' with incorrect JavaDocs. * asm-bom packaging should be 'pom'. * The Textifier prints a supplementary space at the end of each method that throws at least one exception.


    open-test-reporting:
    • Included `open-test-reporting-events` and `open-test-reporting-schema` to the channels as they are runtime dependencies of Junit5 (no source changes)

    saxpath was implemented at version 1.0 FCS:
    • New standalone RPM package implementation, originally part of `jdom` source package (openSUSE Leap 15.5 package only)

    xom was implemented at version 1.3.9:
    • New standalone RPM package implementation, originally part of `jdom` source package
    • The Nodes and Elements classes are iterable so you can use the enhanced for loop syntax on instances of these classes.
    • The copy() method is now covariant.
    • Adds Automatic-Moduole-Name to jar
    • Remove direct dependency on xml-apis:xml-apis artifact since these classes are now available in the core runtime.
    • Eliminate usage of com.sun classes to make XOM compatible with JDK 16.
    • Replace remaining usages of StringBuffer with StringBuilder to slightly improve performance.


    Advisory IDSUSE-SU-2024:1943-1
    ReleasedFri Jun 7 17:04:06 2024
    SummarySecurity update for util-linux
    Typesecurity
    Severityimportant
    References1218609,1220117,1221831,1223605,CVE-2024-28085
    Description:

    This update for util-linux fixes the following issues:

    • CVE-2024-28085: Properly neutralize escape sequences in wall to avoid potential account takeover. (bsc#1221831)


    Advisory IDSUSE-RU-2024:1954-1
    ReleasedFri Jun 7 18:01:06 2024
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1221482
    Description:

    This update for glibc fixes the following issues:

    • Also include stat64 in the 32-bit libc_nonshared.a workaround (bsc#1221482)


    Advisory IDSUSE-RU-2024:1997-1
    ReleasedTue Jun 11 17:24:32 2024
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitymoderate
    References1223596
    Description:

    This update for e2fsprogs fixes the following issues:

    • EA Inode handling fixes: - e2fsck: add more checks for ea inode consistency (bsc#1223596) - e2fsck: fix golden output of several tests (bsc#1223596)


    Advisory IDSUSE-RU-2024:2024-1
    ReleasedThu Jun 13 16:15:18 2024
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1209627
    Description:

    This update for jitterentropy fixes the following issues:

    • Fixed a stack corruption on s390x: [bsc#1209627] * Output size of the STCKE command on s390x is 16 bytes, compared to 8 bytes of the STCK command. Fix a stack corruption in the s390x version of jent_get_nstime(). Add some more detailed information on the STCKE command.

    Updated to 3.4.1
    • add FIPS 140 hints to man page
    • simplify the test tool to search for optimal configurations
    • fix: jent_loop_shuffle: re-add setting the time that was lost with 3.4.0
    • enhancement: add ARM64 assembler code to read high-res timer


    Advisory IDSUSE-SU-2024:2059-1
    ReleasedTue Jun 18 13:11:29 2024
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severityimportant
    References1225551,CVE-2024-4741
    Description:

    This update for openssl-1_1 fixes the following issues:

    • CVE-2024-4741: Fixed a use-after-free with SSL_free_buffers. (bsc#1225551)


    Advisory IDSUSE-SU-2024:2066-1
    ReleasedTue Jun 18 13:16:09 2024
    SummarySecurity update for openssl-3
    Typesecurity
    Severityimportant
    References1223428,1224388,1225291,1225551,CVE-2024-4603,CVE-2024-4741
    Description:

    This update for openssl-3 fixes the following issues:
    Security issues fixed:

    • CVE-2024-4603: Check DSA parameters for excessive sizes before validating (bsc#1224388)
    • CVE-2024-4741: Fixed a use-after-free with SSL_free_buffers. (bsc#1225551)

    Other issues fixed:
    • Enable livepatching support (bsc#1223428)
    • Fix HDKF key derivation (bsc#1225291, gh#openssl/openssl#23448, + gh#openssl/openssl#23456)


    Advisory IDSUSE-RU-2024:2086-1
    ReleasedWed Jun 19 11:48:24 2024
    SummaryRecommended update for gcc13
    Typerecommended
    Severitymoderate
    References1188441
    Description:

    This update for gcc13 fixes the following issues:
    Update to GCC 13.3 release

    • Removed Fiji support from the GCN offload compiler as that is requiring Code Object version 3 which is no longer supported by llvm18.
    • Avoid combine spending too much compile-time and memory doing nothing on s390x. [bsc#1188441]
    • Make requirement to lld version specific to avoid requiring the meta-package.


    Advisory IDSUSE-RU-2024:2214-1
    ReleasedTue Jun 25 17:11:26 2024
    SummaryRecommended update for util-linux
    Typerecommended
    Severitymoderate
    References1225598
    Description:

    This update for util-linux fixes the following issue:

    • Fix hang of lscpu -e (bsc#1225598)


    Advisory IDSUSE-SU-2024:2290-1
    ReleasedWed Jul 3 11:35:00 2024
    SummarySecurity update for libxml2
    Typesecurity
    Severitylow
    References1224282,CVE-2024-34459
    Description:

    This update for libxml2 fixes the following issues:

    • CVE-2024-34459: Fixed buffer over-read in xmlHTMLPrintFileContext in xmllint.c (bsc#1224282).


    Advisory IDSUSE-SU-2024:2307-1
    ReleasedFri Jul 5 12:04:34 2024
    SummarySecurity update for krb5
    Typesecurity
    Severityimportant
    References1227186,1227187,CVE-2024-37370,CVE-2024-37371
    Description:

    This update for krb5 fixes the following issues:

    • CVE-2024-37370: Fixed confidential GSS krb5 wrap tokens with invalid fields were errouneously accepted (bsc#1227186).
    • CVE-2024-37371: Fixed invalid memory read when processing message tokens with invalid length fields (bsc#1227187).


    Advisory IDSUSE-SU-2024:2413-1
    ReleasedThu Jul 11 18:03:44 2024
    SummarySecurity update for tomcat10
    Typesecurity
    Severityimportant
    References1227399,CVE-2024-34750
    Description:

    This update for tomcat10 fixes the following issues:

    • CVE-2024-34750: Fixed an improper handling of exceptional conditions (bsc#1227399).


    Advisory IDSUSE-SU-2024:2578-1
    ReleasedMon Jul 22 12:36:15 2024
    SummarySecurity update for java-21-openjdk
    Typesecurity
    Severityimportant
    References1227298,1228046,1228047,1228048,1228051,1228052,CVE-2024-21131,CVE-2024-21138,CVE-2024-21140,CVE-2024-21145,CVE-2024-21147
    Description:

    This update for java-21-openjdk fixes the following issues:
    Updated to version 21.0.4+7 (July 2024 CPU):

    • CVE-2024-21131: Fixed a potential UTF8 size overflow (bsc#1228046).
    • CVE-2024-21138: Fixed an infinite loop due to excessive symbol length (bsc#1228047).
    • CVE-2024-21140: Fixed a pre-loop limit overflow in Range Check Elimination (bsc#1228048).
    • CVE-2024-21147: Fixed an out-of-bounds access in 2D image handling (bsc#1228052).
    • CVE-2024-21145: Fixed an index overflow in RangeCheckElimination (bsc#1228051).