Vulnerability Scan Report for registry.suse.com/suse/sle15:15.2.9.5.326
Image containing a minimal environment for containers based on SUSE Linux Enterprise Server 15 SP2.
Last scanned on: February 14, 2025 05:44

Image containing a minimal environment for containers based on SUSE Linux Enterprise Server 15 SP2.
Last scanned on: February 14, 2025 05:44
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
libgnutls30-hmac | MEDIUM | fixed |
Security update for gnutls Vulnerability ID: SUSE-SU-2024:0860-1 Installed Version: 3.6.7-150200.14.25.2 Fixed Version: 3.6.7-150200.14.31.1 This update for gnutls fixes the following issues: - CVE-2024-0553: Fixed insufficient mitigation for side channel attack in RSA-PSK, aka CVE-2023-5981 (bsc#1218865). |
||
libgpg-error0 | MEDIUM | fixed |
Security update for skopeo Vulnerability ID: SUSE-SU-2024:2754-1 Installed Version: 1.29-1.8 Fixed Version: 1.29-150000.3.3.1 This update for skopeo fixes the following issues: Update to version 1.14.4: - CVE-2024-3727: Fixed a vulnerability that allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, resource exhaustion, local path traversal and other attacks. (bsc#1224123) |
||
libmount1 | HIGH | fixed |
Security update for util-linux Vulnerability ID: SUSE-SU-2023:4512-1 Installed Version: 2.33.2-150100.4.37.1 Fixed Version: 2.33.2-150100.4.40.1 This update for util-linux fixes the following issues: - CVE-2018-7738: Fixed shell code injection in umount bash-completions (bsc#1213865). |
||
libmount1 | HIGH | fixed |
Security update for util-linux Vulnerability ID: SUSE-SU-2024:1106-1 Installed Version: 2.33.2-150100.4.37.1 Fixed Version: 2.33.2-150100.4.45.1 This update for util-linux fixes the following issues: - CVE-2024-28085: Properly neutralize escape sequences in wall. (bsc#1221831) - Prevent error message if `/var/lib/libuuid/clock.txt` does not exist (bsc#1194642) - Fixed performance degradation (bsc#1207987) |
||
libnghttp2-14 | HIGH | fixed |
Security update for nghttp2 Vulnerability ID: SUSE-SU-2023:3997-1 Installed Version: 1.40.0-6.1 Fixed Version: 1.40.0-150200.9.1 This update for nghttp2 fixes the following issues: - CVE-2023-35945: Fixed memory leak when PUSH_PROMISE or HEADERS frame cannot be sent (bsc#1215713). |