SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:219-1 Container Tags : suse/sles12sp4:26.298 , suse/sles12sp4:latest Container Release : 26.298 Severity : moderate Type : security References : 1175109 1177976 1179398 1179399 1179593 1183933 1186114 CVE-2020-8231 CVE-2020-8284 CVE-2020-8285 CVE-2020-8286 CVE-2021-22876 CVE-2021-22898 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1786-1 Released: Thu May 27 16:45:41 2021 Summary: Security update for curl Type: security Severity: moderate References: 1175109,1177976,1179398,1179399,1179593,1183933,1186114,CVE-2020-8231,CVE-2020-8284,CVE-2020-8285,CVE-2020-8286,CVE-2021-22876,CVE-2021-22898 This update for curl fixes the following issues: - CVE-2021-22898: TELNET stack contents disclosure (bsc#1186114) - CVE-2021-22876: The automatic referer leaks credentials (bsc#1183933) - CVE-2020-8286: Inferior OCSP verification (bsc#1179593) - CVE-2020-8285: FTP wildcard stack overflow (bsc#1179399) - CVE-2020-8284: Trusting FTP PASV responses (bsc#1179398) - CVE-2020-8231: libcurl will pick and use the wrong connection with multiple requests with libcurl's multi API and the 'CURLOPT_CONNECT_ONLY' option (bsc#1175109) - Fix: SFTP uploads result in empty uploaded files (bsc#1177976) The following package changes have been done: - base-container-licenses-3.0-1.212 updated - container-suseconnect-2.0.0-1.113 updated - libcurl4-7.60.0-4.20.1 updated