SUSE Container Update Advisory: ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:670-1 Container Tags : suse/sle-micro-rancher/5.3:latest Container Release : 7.2.324 Severity : important Type : security References : 1216198 1218215 CVE-2023-51385 CVE-2023-5388 ----------------------------------------------------------------- The container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:596-1 Released: Thu Feb 22 20:05:29 2024 Summary: Security update for openssh Type: security Severity: important References: 1218215,CVE-2023-51385 This update for openssh fixes the following issues: - CVE-2023-51385: Limit the use of shell metacharacters in host- and user names to avoid command injection. (bsc#1218215) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:597-1 Released: Thu Feb 22 20:07:11 2024 Summary: Security update for mozilla-nss Type: security Severity: important References: 1216198,CVE-2023-5388 This update for mozilla-nss fixes the following issues: Update to NSS 3.90.2: - CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198) The following package changes have been done: - libfreebl3-3.90.2-150400.3.39.1 updated - libsoftokn3-3.90.2-150400.3.39.1 updated - mozilla-nss-certs-3.90.2-150400.3.39.1 updated - mozilla-nss-3.90.2-150400.3.39.1 updated - openssh-clients-8.4p1-150300.3.30.1 updated - openssh-common-8.4p1-150300.3.30.1 updated - openssh-server-8.4p1-150300.3.30.1 updated - openssh-8.4p1-150300.3.30.1 updated