Vulnerability Scan Report for registry.suse.com/bci/golang:1.20-2.21
Go 1.21 development container based on the SLE Base Container Image.
Last scanned on: November 03, 2024 00:51
Go 1.21 development container based on the SLE Base Container Image.
Last scanned on: November 03, 2024 00:51
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2023:3397-1 Installed Version: 1.1.1l-150400.7.31.2 Fixed Version: 1.1.1l-150400.7.53.1 This update for openssl-1_1 fixes the following issues: - CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853) - Don't pass zero length input to EVP_Cipher because s390x assembler optimized AES cannot handle zero size. (bsc#1213517) |
||
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2023:4524-1 Installed Version: 1.1.1l-150400.7.31.2 Fixed Version: 1.1.1l-150400.7.60.2 This update for openssl-1_1 fixes the following issues: - CVE-2023-5678: Fixed generating and checking of excessively long X9.42 DH keys that resulted in a possible Denial of Service (bsc#1216922). |
||
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2024:1949-1 Installed Version: 1.1.1l-150400.7.31.2 Fixed Version: 1.1.1l-150400.7.66.2 This update for openssl-1_1 fixes the following issues: - CVE-2024-2511: Fixed unconstrained session cache growth in TLSv1.3 (bsc#1222548). |
||
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2024:2927-1 Installed Version: 1.1.1l-150400.7.31.2 Fixed Version: 1.1.1l-150400.7.72.1 This update for openssl-1_1 fixes the following issues: - CVE-2024-5535: Fixed a buffer overread in function SSL_select_next_proto() with an empty supported client protocols buffer (bsc#1227138) Other fixes: - Build with no-afalgeng (bsc#1226463) |
||
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2024:3872-1 Installed Version: 1.1.1l-150400.7.31.2 Fixed Version: 1.1.1l-150400.7.75.1 This update for openssl-1_1 fixes the following issues: - CVE-2023-50782: Implicit rejection in PKCS#1 v1.5 (bsc#1220262) |