[SUSE-SU-2017:2699-1] Security update for SLES 12 Docker image

Severity Important
CVEs 140

Security update for SLES 12 Docker image

The SUSE Linux Enterprise Server 12 container image has been updated to include
security and stability fixes.

The following issues related to building of the container images have been fixed:

  • Included krb5 package to avoid the inclusion of krb5-mini which gets selected as a dependency by the Build Service solver. (bsc#1056193)
  • Do not install recommended packages when building container images. (bsc#975726)

A number of security issues that have been already fixed by updates released for
SUSE Linux Enterprise Server 12 are now included in the base image. A package/CVE
cross-reference is available below.

pam:

  • CVE-2015-3238

libtasn1:

  • CVE-2015-3622
  • CVE-2016-4008

libidn:

  • CVE-2015-2059
  • CVE-2015-8948
  • CVE-2016-6261
  • CVE-2016-6262
  • CVE-2016-6263

zlib:

  • CVE-2016-9840
  • CVE-2016-9841
  • CVE-2016-9842
  • CVE-2016-9843

curl:

  • CVE-2016-5419
  • CVE-2016-5420
  • CVE-2016-5421
  • CVE-2016-7141
  • CVE-2016-7167
  • CVE-2016-8615
  • CVE-2016-8616
  • CVE-2016-8617
  • CVE-2016-8618
  • CVE-2016-8619
  • CVE-2016-8620
  • CVE-2016-8621
  • CVE-2016-8622
  • CVE-2016-8623
  • CVE-2016-8624
  • CVE-2016-9586
  • CVE-2017-1000100
  • CVE-2017-1000101
  • CVE-2017-7407

openssl:

  • CVE-2016-2105
  • CVE-2016-2106
  • CVE-2016-2107
  • CVE-2016-2108
  • CVE-2016-2109
  • CVE-2016-2177
  • CVE-2016-2178
  • CVE-2016-2179
  • CVE-2016-2180
  • CVE-2016-2181
  • CVE-2016-2182
  • CVE-2016-2183
  • CVE-2016-6302
  • CVE-2016-6303
  • CVE-2016-6304
  • CVE-2016-6306

libxml2:

  • CVE-2014-0191
  • CVE-2015-8806
  • CVE-2016-1762
  • CVE-2016-1833
  • CVE-2016-1834
  • CVE-2016-1835
  • CVE-2016-1837
  • CVE-2016-1838
  • CVE-2016-1839
  • CVE-2016-1840
  • CVE-2016-2073
  • CVE-2016-3627
  • CVE-2016-3705
  • CVE-2016-4447
  • CVE-2016-4448
  • CVE-2016-4449
  • CVE-2016-4483
  • CVE-2016-4658
  • CVE-2016-9318
  • CVE-2016-9597
  • CVE-2017-9047
  • CVE-2017-9048
  • CVE-2017-9049
  • CVE-2017-9050

util-linux:

  • CVE-2015-5218
  • CVE-2016-5011
  • CVE-2017-2616

cracklib:

  • CVE-2016-6318

systemd:

  • CVE-2014-9770
  • CVE-2015-8842
  • CVE-2016-7796

pcre:

  • CVE-2014-8964
  • CVE-2015-2325
  • CVE-2015-2327
  • CVE-2015-2328
  • CVE-2015-3210
  • CVE-2015-3217
  • CVE-2015-5073
  • CVE-2015-8380
  • CVE-2015-8381
  • CVE-2015-8382
  • CVE-2015-8383
  • CVE-2015-8384
  • CVE-2015-8385
  • CVE-2015-8386
  • CVE-2015-8387
  • CVE-2015-8388
  • CVE-2015-8389
  • CVE-2015-8390
  • CVE-2015-8391
  • CVE-2015-8392
  • CVE-2015-8393
  • CVE-2015-8394
  • CVE-2015-8395
  • CVE-2016-1283
  • CVE-2016-3191

appamor:

  • CVE-2017-6507

bash:

  • CVE-2014-6277
  • CVE-2014-6278
  • CVE-2016-0634
  • CVE-2016-7543

cpio:

  • CVE-2016-2037

glibc:

  • CVE-2016-1234
  • CVE-2016-3075
  • CVE-2016-3706
  • CVE-2016-4429
  • CVE-2017-1000366

perl:

  • CVE-2015-8853
  • CVE-2016-1238
  • CVE-2016-2381
  • CVE-2016-6185

libssh2_org:

  • CVE-2016-0787

expat:

  • CVE-2012-6702
  • CVE-2015-1283
  • CVE-2016-0718
  • CVE-2016-5300
  • CVE-2016-9063
  • CVE-2017-9233

ncurses:

  • CVE-2017-10684
  • CVE-2017-10685
  • CVE-2017-11112
  • CVE-2017-11113

libksba:

  • CVE-2016-4574
  • CVE-2016-4579

libgcrypt:

  • CVE-2015-7511
  • CVE-2016-6313
  • CVE-2017-7526

dbus-1:

  • CVE-2014-7824
  • CVE-2015-0245

Finally, the following packages received non-security fixes:

  • augeas
  • bzip2
  • ca-certificates-mozilla
  • coreutils
  • cryptsetup
  • cyrus-sasl
  • dirmngr
  • e2fsprogs
  • findutils
  • gpg2
  • insserv-compat
  • kmod
  • libcap
  • libsolv
  • libzypp
  • openldap2
  • p11-kit
  • permissions
  • procps
  • rpm
  • sed
  • shadow
  • zypper
ID
SUSE-SU-2017:2699-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2017/suse-su-20172699-1/
Published
2017-10-10T19:37:24
(7 years ago)
Modified
2017-10-10T19:37:24
(7 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/suse-su-2017_2699-1.json
Suse URL for SUSE-SU-2017:2699-1 https://www.suse.com/support/update/announcement/2017/suse-su-20172699-1/
Suse E-Mail link for SUSE-SU-2017:2699-1 https://lists.suse.com/pipermail/sle-security-updates/2017-October/003288.html
Bugzilla SUSE Bug 1056193 https://bugzilla.suse.com/1056193
Bugzilla SUSE Bug 975726 https://bugzilla.suse.com/975726
CVE SUSE CVE CVE-2012-6702 page https://www.suse.com/security/cve/CVE-2012-6702/
CVE SUSE CVE CVE-2014-0191 page https://www.suse.com/security/cve/CVE-2014-0191/
CVE SUSE CVE CVE-2014-6271 page https://www.suse.com/security/cve/CVE-2014-6271/
CVE SUSE CVE CVE-2014-6277 page https://www.suse.com/security/cve/CVE-2014-6277/
CVE SUSE CVE CVE-2014-6278 page https://www.suse.com/security/cve/CVE-2014-6278/
CVE SUSE CVE CVE-2014-7169 page https://www.suse.com/security/cve/CVE-2014-7169/
CVE SUSE CVE CVE-2014-7187 page https://www.suse.com/security/cve/CVE-2014-7187/
CVE SUSE CVE CVE-2014-7824 page https://www.suse.com/security/cve/CVE-2014-7824/
CVE SUSE CVE CVE-2014-8964 page https://www.suse.com/security/cve/CVE-2014-8964/
CVE SUSE CVE CVE-2014-9770 page https://www.suse.com/security/cve/CVE-2014-9770/
CVE SUSE CVE CVE-2015-0245 page https://www.suse.com/security/cve/CVE-2015-0245/
CVE SUSE CVE CVE-2015-1283 page https://www.suse.com/security/cve/CVE-2015-1283/
CVE SUSE CVE CVE-2015-2059 page https://www.suse.com/security/cve/CVE-2015-2059/
CVE SUSE CVE CVE-2015-2325 page https://www.suse.com/security/cve/CVE-2015-2325/
CVE SUSE CVE CVE-2015-2327 page https://www.suse.com/security/cve/CVE-2015-2327/
CVE SUSE CVE CVE-2015-2328 page https://www.suse.com/security/cve/CVE-2015-2328/
CVE SUSE CVE CVE-2015-3210 page https://www.suse.com/security/cve/CVE-2015-3210/
CVE SUSE CVE CVE-2015-3217 page https://www.suse.com/security/cve/CVE-2015-3217/
CVE SUSE CVE CVE-2015-3238 page https://www.suse.com/security/cve/CVE-2015-3238/
CVE SUSE CVE CVE-2015-3622 page https://www.suse.com/security/cve/CVE-2015-3622/
CVE SUSE CVE CVE-2015-5073 page https://www.suse.com/security/cve/CVE-2015-5073/
CVE SUSE CVE CVE-2015-5218 page https://www.suse.com/security/cve/CVE-2015-5218/
CVE SUSE CVE CVE-2015-5276 page https://www.suse.com/security/cve/CVE-2015-5276/
CVE SUSE CVE CVE-2015-7511 page https://www.suse.com/security/cve/CVE-2015-7511/
CVE SUSE CVE CVE-2015-8380 page https://www.suse.com/security/cve/CVE-2015-8380/
CVE SUSE CVE CVE-2015-8381 page https://www.suse.com/security/cve/CVE-2015-8381/
CVE SUSE CVE CVE-2015-8382 page https://www.suse.com/security/cve/CVE-2015-8382/
CVE SUSE CVE CVE-2015-8383 page https://www.suse.com/security/cve/CVE-2015-8383/
CVE SUSE CVE CVE-2015-8384 page https://www.suse.com/security/cve/CVE-2015-8384/
CVE SUSE CVE CVE-2015-8385 page https://www.suse.com/security/cve/CVE-2015-8385/
CVE SUSE CVE CVE-2015-8386 page https://www.suse.com/security/cve/CVE-2015-8386/
CVE SUSE CVE CVE-2015-8387 page https://www.suse.com/security/cve/CVE-2015-8387/
CVE SUSE CVE CVE-2015-8388 page https://www.suse.com/security/cve/CVE-2015-8388/
CVE SUSE CVE CVE-2015-8389 page https://www.suse.com/security/cve/CVE-2015-8389/
CVE SUSE CVE CVE-2015-8390 page https://www.suse.com/security/cve/CVE-2015-8390/
CVE SUSE CVE CVE-2015-8391 page https://www.suse.com/security/cve/CVE-2015-8391/
CVE SUSE CVE CVE-2015-8392 page https://www.suse.com/security/cve/CVE-2015-8392/
CVE SUSE CVE CVE-2015-8393 page https://www.suse.com/security/cve/CVE-2015-8393/
CVE SUSE CVE CVE-2015-8394 page https://www.suse.com/security/cve/CVE-2015-8394/
CVE SUSE CVE CVE-2015-8395 page https://www.suse.com/security/cve/CVE-2015-8395/
CVE SUSE CVE CVE-2015-8806 page https://www.suse.com/security/cve/CVE-2015-8806/
CVE SUSE CVE CVE-2015-8842 page https://www.suse.com/security/cve/CVE-2015-8842/
CVE SUSE CVE CVE-2015-8853 page https://www.suse.com/security/cve/CVE-2015-8853/
CVE SUSE CVE CVE-2015-8948 page https://www.suse.com/security/cve/CVE-2015-8948/
CVE SUSE CVE CVE-2016-0634 page https://www.suse.com/security/cve/CVE-2016-0634/
CVE SUSE CVE CVE-2016-0718 page https://www.suse.com/security/cve/CVE-2016-0718/
CVE SUSE CVE CVE-2016-0787 page https://www.suse.com/security/cve/CVE-2016-0787/
CVE SUSE CVE CVE-2016-1234 page https://www.suse.com/security/cve/CVE-2016-1234/
CVE SUSE CVE CVE-2016-1238 page https://www.suse.com/security/cve/CVE-2016-1238/
CVE SUSE CVE CVE-2016-1283 page https://www.suse.com/security/cve/CVE-2016-1283/
CVE SUSE CVE CVE-2016-1762 page https://www.suse.com/security/cve/CVE-2016-1762/
CVE SUSE CVE CVE-2016-1833 page https://www.suse.com/security/cve/CVE-2016-1833/
CVE SUSE CVE CVE-2016-1834 page https://www.suse.com/security/cve/CVE-2016-1834/
CVE SUSE CVE CVE-2016-1835 page https://www.suse.com/security/cve/CVE-2016-1835/
CVE SUSE CVE CVE-2016-1837 page https://www.suse.com/security/cve/CVE-2016-1837/
CVE SUSE CVE CVE-2016-1838 page https://www.suse.com/security/cve/CVE-2016-1838/
CVE SUSE CVE CVE-2016-1839 page https://www.suse.com/security/cve/CVE-2016-1839/
CVE SUSE CVE CVE-2016-1840 page https://www.suse.com/security/cve/CVE-2016-1840/
CVE SUSE CVE CVE-2016-2037 page https://www.suse.com/security/cve/CVE-2016-2037/
CVE SUSE CVE CVE-2016-2073 page https://www.suse.com/security/cve/CVE-2016-2073/
CVE SUSE CVE CVE-2016-2105 page https://www.suse.com/security/cve/CVE-2016-2105/
CVE SUSE CVE CVE-2016-2106 page https://www.suse.com/security/cve/CVE-2016-2106/
CVE SUSE CVE CVE-2016-2107 page https://www.suse.com/security/cve/CVE-2016-2107/
CVE SUSE CVE CVE-2016-2108 page https://www.suse.com/security/cve/CVE-2016-2108/
CVE SUSE CVE CVE-2016-2109 page https://www.suse.com/security/cve/CVE-2016-2109/
CVE SUSE CVE CVE-2016-2177 page https://www.suse.com/security/cve/CVE-2016-2177/
CVE SUSE CVE CVE-2016-2178 page https://www.suse.com/security/cve/CVE-2016-2178/
CVE SUSE CVE CVE-2016-2179 page https://www.suse.com/security/cve/CVE-2016-2179/
CVE SUSE CVE CVE-2016-2180 page https://www.suse.com/security/cve/CVE-2016-2180/
CVE SUSE CVE CVE-2016-2181 page https://www.suse.com/security/cve/CVE-2016-2181/
CVE SUSE CVE CVE-2016-2182 page https://www.suse.com/security/cve/CVE-2016-2182/
CVE SUSE CVE CVE-2016-2183 page https://www.suse.com/security/cve/CVE-2016-2183/
CVE SUSE CVE CVE-2016-2381 page https://www.suse.com/security/cve/CVE-2016-2381/
CVE SUSE CVE CVE-2016-3075 page https://www.suse.com/security/cve/CVE-2016-3075/
CVE SUSE CVE CVE-2016-3191 page https://www.suse.com/security/cve/CVE-2016-3191/
CVE SUSE CVE CVE-2016-3627 page https://www.suse.com/security/cve/CVE-2016-3627/
CVE SUSE CVE CVE-2016-3705 page https://www.suse.com/security/cve/CVE-2016-3705/
CVE SUSE CVE CVE-2016-3706 page https://www.suse.com/security/cve/CVE-2016-3706/
CVE SUSE CVE CVE-2016-4008 page https://www.suse.com/security/cve/CVE-2016-4008/
CVE SUSE CVE CVE-2016-4429 page https://www.suse.com/security/cve/CVE-2016-4429/
CVE SUSE CVE CVE-2016-4447 page https://www.suse.com/security/cve/CVE-2016-4447/
CVE SUSE CVE CVE-2016-4448 page https://www.suse.com/security/cve/CVE-2016-4448/
CVE SUSE CVE CVE-2016-4449 page https://www.suse.com/security/cve/CVE-2016-4449/
CVE SUSE CVE CVE-2016-4483 page https://www.suse.com/security/cve/CVE-2016-4483/
CVE SUSE CVE CVE-2016-4574 page https://www.suse.com/security/cve/CVE-2016-4574/
CVE SUSE CVE CVE-2016-4579 page https://www.suse.com/security/cve/CVE-2016-4579/
CVE SUSE CVE CVE-2016-4658 page https://www.suse.com/security/cve/CVE-2016-4658/
CVE SUSE CVE CVE-2016-5011 page https://www.suse.com/security/cve/CVE-2016-5011/
CVE SUSE CVE CVE-2016-5300 page https://www.suse.com/security/cve/CVE-2016-5300/
CVE SUSE CVE CVE-2016-5419 page https://www.suse.com/security/cve/CVE-2016-5419/
CVE SUSE CVE CVE-2016-5420 page https://www.suse.com/security/cve/CVE-2016-5420/
CVE SUSE CVE CVE-2016-5421 page https://www.suse.com/security/cve/CVE-2016-5421/
CVE SUSE CVE CVE-2016-6185 page https://www.suse.com/security/cve/CVE-2016-6185/
CVE SUSE CVE CVE-2016-6261 page https://www.suse.com/security/cve/CVE-2016-6261/
CVE SUSE CVE CVE-2016-6262 page https://www.suse.com/security/cve/CVE-2016-6262/
CVE SUSE CVE CVE-2016-6263 page https://www.suse.com/security/cve/CVE-2016-6263/
CVE SUSE CVE CVE-2016-6302 page https://www.suse.com/security/cve/CVE-2016-6302/
CVE SUSE CVE CVE-2016-6303 page https://www.suse.com/security/cve/CVE-2016-6303/
CVE SUSE CVE CVE-2016-6304 page https://www.suse.com/security/cve/CVE-2016-6304/
CVE SUSE CVE CVE-2016-6306 page https://www.suse.com/security/cve/CVE-2016-6306/
CVE SUSE CVE CVE-2016-6313 page https://www.suse.com/security/cve/CVE-2016-6313/
CVE SUSE CVE CVE-2016-6318 page https://www.suse.com/security/cve/CVE-2016-6318/
CVE SUSE CVE CVE-2016-7141 page https://www.suse.com/security/cve/CVE-2016-7141/
CVE SUSE CVE CVE-2016-7167 page https://www.suse.com/security/cve/CVE-2016-7167/
CVE SUSE CVE CVE-2016-7543 page https://www.suse.com/security/cve/CVE-2016-7543/
CVE SUSE CVE CVE-2016-7796 page https://www.suse.com/security/cve/CVE-2016-7796/
CVE SUSE CVE CVE-2016-8615 page https://www.suse.com/security/cve/CVE-2016-8615/
CVE SUSE CVE CVE-2016-8616 page https://www.suse.com/security/cve/CVE-2016-8616/
CVE SUSE CVE CVE-2016-8617 page https://www.suse.com/security/cve/CVE-2016-8617/
CVE SUSE CVE CVE-2016-8618 page https://www.suse.com/security/cve/CVE-2016-8618/
CVE SUSE CVE CVE-2016-8619 page https://www.suse.com/security/cve/CVE-2016-8619/
CVE SUSE CVE CVE-2016-8620 page https://www.suse.com/security/cve/CVE-2016-8620/
CVE SUSE CVE CVE-2016-8621 page https://www.suse.com/security/cve/CVE-2016-8621/
CVE SUSE CVE CVE-2016-8622 page https://www.suse.com/security/cve/CVE-2016-8622/
CVE SUSE CVE CVE-2016-8623 page https://www.suse.com/security/cve/CVE-2016-8623/
CVE SUSE CVE CVE-2016-8624 page https://www.suse.com/security/cve/CVE-2016-8624/
CVE SUSE CVE CVE-2016-9063 page https://www.suse.com/security/cve/CVE-2016-9063/
CVE SUSE CVE CVE-2016-9318 page https://www.suse.com/security/cve/CVE-2016-9318/
CVE SUSE CVE CVE-2016-9586 page https://www.suse.com/security/cve/CVE-2016-9586/
CVE SUSE CVE CVE-2016-9597 page https://www.suse.com/security/cve/CVE-2016-9597/
CVE SUSE CVE CVE-2016-9840 page https://www.suse.com/security/cve/CVE-2016-9840/
CVE SUSE CVE CVE-2016-9841 page https://www.suse.com/security/cve/CVE-2016-9841/
CVE SUSE CVE CVE-2016-9842 page https://www.suse.com/security/cve/CVE-2016-9842/
CVE SUSE CVE CVE-2016-9843 page https://www.suse.com/security/cve/CVE-2016-9843/
CVE SUSE CVE CVE-2017-1000100 page https://www.suse.com/security/cve/CVE-2017-1000100/
CVE SUSE CVE CVE-2017-1000101 page https://www.suse.com/security/cve/CVE-2017-1000101/
CVE SUSE CVE CVE-2017-1000366 page https://www.suse.com/security/cve/CVE-2017-1000366/
CVE SUSE CVE CVE-2017-10684 page https://www.suse.com/security/cve/CVE-2017-10684/
CVE SUSE CVE CVE-2017-10685 page https://www.suse.com/security/cve/CVE-2017-10685/
CVE SUSE CVE CVE-2017-11112 page https://www.suse.com/security/cve/CVE-2017-11112/
CVE SUSE CVE CVE-2017-11113 page https://www.suse.com/security/cve/CVE-2017-11113/
CVE SUSE CVE CVE-2017-2616 page https://www.suse.com/security/cve/CVE-2017-2616/
CVE SUSE CVE CVE-2017-6507 page https://www.suse.com/security/cve/CVE-2017-6507/
CVE SUSE CVE CVE-2017-7407 page https://www.suse.com/security/cve/CVE-2017-7407/
CVE SUSE CVE CVE-2017-7526 page https://www.suse.com/security/cve/CVE-2017-7526/
CVE SUSE CVE CVE-2017-9047 page https://www.suse.com/security/cve/CVE-2017-9047/
CVE SUSE CVE CVE-2017-9048 page https://www.suse.com/security/cve/CVE-2017-9048/
CVE SUSE CVE CVE-2017-9049 page https://www.suse.com/security/cve/CVE-2017-9049/
CVE SUSE CVE CVE-2017-9050 page https://www.suse.com/security/cve/CVE-2017-9050/
CVE SUSE CVE CVE-2017-9233 page https://www.suse.com/security/cve/CVE-2017-9233/
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...