SUSE Container Update Advisory: ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3584-1 Container Tags : suse/sle-micro-rancher/5.4:latest Container Release : 3.2.133 Severity : important Type : security References : 1216268 1216432 1216433 CVE-2023-34058 CVE-2023-34059 CVE-2023-46228 ----------------------------------------------------------------- The container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4225-1 Released: Fri Oct 27 11:02:14 2023 Summary: Security update for zchunk Type: security Severity: important References: 1216268,CVE-2023-46228 This update for zchunk fixes the following issues: - CVE-2023-46228: Fixed a handle overflow errors in malformed zchunk files. (bsc#1216268) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4227-1 Released: Fri Oct 27 11:26:20 2023 Summary: Security update for open-vm-tools Type: security Severity: important References: 1216432,1216433,CVE-2023-34058,CVE-2023-34059 This update for open-vm-tools fixes the following issues: - CVE-2023-34058: Fixed a SAML token signature bypass issue (bsc#1216432). - CVE-2023-34059: Fixed a privilege escalation issue through vmware-user-suid-wrapper (bsc#1216433). The following package changes have been done: - libvmtools0-12.3.0-150300.43.1 updated - libzck1-1.1.16-150400.3.7.1 updated - open-vm-tools-12.3.0-150300.43.1 updated