FlawAtlas
Search the atlas
SUSE-SU-2023:0871-1 Not scored

Security update for container-suseconnect

This update of container-suseconnect fixes the following issue: - container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7. - CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270). - CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271). - CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272). - CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030). - CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134).

Exploit probability Not scored
Published March 22, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7 container-suseconnect
SUSE:Enterprise Storage 7.1 container-suseconnect
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS container-suseconnect
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS container-suseconnect
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS container-suseconnect
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS container-suseconnect
SUSE:Linux Enterprise Module for Containers 15 SP4 container-suseconnect
SUSE:Linux Enterprise Server 15 SP1-LTSS container-suseconnect
SUSE:Linux Enterprise Server 15 SP2-LTSS container-suseconnect
SUSE:Linux Enterprise Server 15 SP3-LTSS container-suseconnect
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 container-suseconnect
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 container-suseconnect
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 container-suseconnect

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:0871-1

This update of container-suseconnect fixes the following issue: - container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7. - CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270). - CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271). - CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272). - CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030). - CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134).

View original source

05 / REFERENCES

Further evidence