Vulnerability Scan Report for registry.suse.com/bci/bci-init:15.5.16.5
Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: March 08, 2025 11:02

Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: March 08, 2025 11:02
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
libexpat1 | MEDIUM | fixed |
Security update for expat Vulnerability ID: SUSE-SU-2024:3216-1 Installed Version: 2.4.4-150400.3.17.1 Fixed Version: 2.4.4-150400.3.22.1 This update for expat fixes the following issues: - CVE-2024-45492: integer overflow in function nextScaffoldPart. (bsc#1229932) - CVE-2024-45491: integer overflow in dtdCopy. (bsc#1229931) - CVE-2024-45490: negative length for XML_ParseBuffer not rejected. (bsc#1229930) |
||
libexpat1 | MEDIUM | fixed |
Security update for expat Vulnerability ID: SUSE-SU-2024:4035-1 Installed Version: 2.4.4-150400.3.17.1 Fixed Version: 2.4.4-150400.3.25.1 This update for expat fixes the following issues: - CVE-2024-50602: Fixed a denial of service via XML_ResumeParser (bsc#1232579). |
||
libglib-2_0-0 | HIGH | fixed |
Security update for glib2 Vulnerability ID: SUSE-SU-2024:4078-1 Installed Version: 2.70.5-150400.3.8.1 Fixed Version: 2.70.5-150400.3.17.1 This update for glib2 fixes the following issues: - CVE-2024-52533: Fixed a single byte buffer overflow (bsc#1233282). |
||
libglib-2_0-0 | LOW | fixed |
Security update for glib2 Vulnerability ID: SUSE-SU-2024:1830-1 Installed Version: 2.70.5-150400.3.8.1 Fixed Version: 2.70.5-150400.3.11.1 This update for glib2 fixes the following issues: - CVE-2024-34397: Fixed signal subscription unicast spoofing vulnerability (bsc#1224044). |
||
libglib-2_0-0 | LOW | fixed |
Security update for glib2 Vulnerability ID: SUSE-SU-2024:3086-1 Installed Version: 2.70.5-150400.3.8.1 Fixed Version: 2.70.5-150400.3.14.1 This update for glib2 fixes the following issues: - Fixed a possible use after free regression introduced by CVE-2024-34397 patch (bsc#1224044). |