Vulnerability Scan Report for registry.suse.com/suse/postgres:14-24.9
PostgreSQL 15 container based on the SLE Base Container Image.
Last scanned on: June 27, 2025 12:52

PostgreSQL 15 container based on the SLE Base Container Image.
Last scanned on: June 27, 2025 12:52
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2025:0349-1 Installed Version: 1.1.1l-150400.7.57.1 Fixed Version: 1.1.1l-150400.7.78.1 This update for openssl-1_1 fixes the following issues: - CVE-2024-13176: Fixed timing side-channel in the ECDSA signature computation (bsc#1236136) |
||
openssl-1_1 | LOW | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2024:0833-1 Installed Version: 1.1.1l-150400.7.57.1 Fixed Version: 1.1.1l-150400.7.63.1 This update for openssl-1_1 fixes the following issues: - CVE-2024-0727: Denial of service when processing a maliciously formatted PKCS12 file (bsc#1219243). |
||
pam | HIGH | fixed |
Security update for pam Vulnerability ID: SUSE-SU-2025:02013-1 Installed Version: 1.3.0-150000.6.61.1 Fixed Version: 1.3.0-150000.6.83.1 This update for pam fixes the following issues: - CVE-2025-6018: pam_env: Change the default to not read the user .pam_environment file (bsc#1243226). - CVE-2025-6020: pam_namespace: convert functions that may operate on a user-controlled path to operate on file descriptors instead of absolute path (bsc#1244509). |
||
pam | MEDIUM | fixed |
Security update for pam Vulnerability ID: SUSE-SU-2024:0136-1 Installed Version: 1.3.0-150000.6.61.1 Fixed Version: 1.3.0-150000.6.66.1 This update for pam fixes the following issues: - CVE-2024-22365: Fixed a local denial of service during PAM login due to a missing check during path manipulation (bsc#1218475). - Check localtime_r() return value to fix crashing (bsc#1217000) |
||
pam-config | HIGH | fixed |
Security update for pam-config Vulnerability ID: SUSE-SU-2025:02082-1 Installed Version: 1.1-3.3.1 Fixed Version: 1.1-150200.3.14.1 This update for pam-config fixes the following issues: - CVE-2025-6018: Stop adding pam_env in AUTH stack, and be sure to put this module at the really end of the SESSION stack (bsc#1243226). |