Security update for govulncheck-vulndb

Announcement ID: SUSE-SU-2024:3911-1
Release Date: 2024-11-05T07:45:06Z
Rating: important
References:
Cross-References:
CVSS scores:
  • CVE-2023-22644 ( NVD ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2023-22644 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • CVE-2023-22644 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-10214 ( NVD ): 3.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
  • CVE-2024-10241 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • CVE-2024-22030 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
  • CVE-2024-36814 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
  • CVE-2024-38365 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
  • CVE-2024-39223 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-47003 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • CVE-2024-47003 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
  • CVE-2024-47067 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-47182 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  • CVE-2024-47182 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • CVE-2024-47534 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-47534 ( NVD ): 0.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
  • CVE-2024-47616 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
  • CVE-2024-47825 ( NVD ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
  • CVE-2024-47827 ( NVD ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • CVE-2024-47832 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-47877 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-48909 ( NVD ): 2.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
  • CVE-2024-48909 ( NVD ): 2.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
  • CVE-2024-48921 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-49380 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-49381 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-49753 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
  • CVE-2024-49757 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • CVE-2024-50312 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • CVE-2024-50312 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • CVE-2024-50312 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • CVE-2024-7558 ( NVD ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
  • CVE-2024-7594 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-8037 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
  • CVE-2024-8038 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
  • CVE-2024-8901 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-8901 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
  • CVE-2024-8975 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  • CVE-2024-8975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-8996 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  • CVE-2024-8996 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-9180 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-9180 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-9264 ( SUSE ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-9264 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • CVE-2024-9264 ( NVD ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • CVE-2024-9264 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-9264 ( NVD ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • CVE-2024-9312 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
  • CVE-2024-9313 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-9341 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
  • CVE-2024-9341 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
  • CVE-2024-9341 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
  • CVE-2024-9355 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
  • CVE-2024-9407 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
  • CVE-2024-9407 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
  • CVE-2024-9407 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N
  • CVE-2024-9486 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • CVE-2024-9594 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
  • CVE-2024-9675 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
  • CVE-2024-9675 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
  • CVE-2024-9675 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products:
  • openSUSE Leap 15.5
  • openSUSE Leap 15.6
  • SUSE Linux Enterprise Desktop 15 SP5
  • SUSE Linux Enterprise Desktop 15 SP6
  • SUSE Linux Enterprise High Performance Computing 15 SP5
  • SUSE Linux Enterprise Micro 5.5
  • SUSE Linux Enterprise Real Time 15 SP5
  • SUSE Linux Enterprise Real Time 15 SP6
  • SUSE Linux Enterprise Server 15 SP5
  • SUSE Linux Enterprise Server 15 SP6
  • SUSE Linux Enterprise Server for SAP Applications 15 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • SUSE Package Hub 15 15-SP5
  • SUSE Package Hub 15 15-SP6

An update that solves 44 vulnerabilities and contains one feature can now be installed.

Description:

This update for govulncheck-vulndb fixes the following issues:

Update to version 0.0.20241030T212825 2024-10-30T21:28:25Z ( jsc#PED-11136 )

  • Go CVE Numbering Authority IDs added or updated with aliases:

  • GO-2024-3230 CVE-2024-48921 GHSA-qjvc-p88j-j9rm

  • GO-2024-3232 CVE-2024-10241 GHSA-6mvp-gh77-7vwh

  • Go CVE Numbering Authority IDs added or updated with aliases:

  • GO-2024-3226 CVE-2024-47827 GHSA-ghjw-32xw-ffwr

  • GO-2024-3227 CVE-2024-10214 GHSA-hm57-h27x-599c
  • GO-2024-3228 GHSA-wcx9-ccpj-hx3c

  • Go CVE Numbering Authority IDs added or updated with aliases:

  • GO-2024-3207 GHSA-p5wf-cmr4-xrwr

  • GO-2024-3208 CVE-2024-47825 GHSA-3wwx-63fv-pfq6
  • GO-2024-3210 CVE-2024-8901
  • GO-2024-3211 CVE-2024-50312
  • GO-2024-3212 GHSA-rjfv-pjvx-mjgv
  • GO-2024-3213 CVE-2024-49380
  • GO-2024-3214 CVE-2024-49381
  • GO-2024-3215 CVE-2024-9264 GHSA-q99m-qcv4-fpm7
  • GO-2024-3216 CVE-2024-49753 GHSA-6cf5-w9h3-4rqv
  • GO-2024-3217 CVE-2024-49757 GHSA-3rmw-76m6-4gjc
  • GO-2024-3219 GHSA-7h65-4p22-39j6
  • GO-2024-3220 CVE-2023-32197 GHSA-7h8m-pvw3-5gh4
  • GO-2024-3221 CVE-2024-22036 GHSA-h99m-6755-rgwc
  • GO-2024-3222 GHSA-x7xj-jvwp-97rv
  • GO-2024-3223 CVE-2022-45157 GHSA-xj7w-r753-vj8v
  • GO-2024-3224 CVE-2024-39223 GHSA-8wxx-35qc-vp6r

  • Go CVE Numbering Authority IDs added or updated with aliases:

  • GO-2024-3189 CVE-2024-38365 GHSA-27vh-h6mc-q6g8

  • GO-2024-3203 CVE-2024-9486
  • GO-2024-3204 CVE-2024-9594

  • Go CVE Numbering Authority IDs added or updated with aliases:

  • GO-2024-3189 CVE-2024-38365 GHSA-27vh-h6mc-q6g8

  • GO-2024-3196 CVE-2024-47877 GHSA-8rm2-93mq-jqhc
  • GO-2024-3199 GHSA-vv6c-69r6-chg9
  • GO-2024-3200 CVE-2024-48909 GHSA-3c32-4hq9-6wgj
  • GO-2024-3201 CVE-2023-22644
  • Go CVE Numbering Authority IDs added or updated with aliases:

  • GO-2024-3166 CVE-2024-47534 GHSA-4f8r-qqr9-fq8j

  • GO-2024-3171 CVE-2024-9341 GHSA-mc76-5925-c5p6

  • Go CVE Numbering Authority IDs added or updated with aliases:

  • GO-2024-3161 CVE-2024-22030 GHSA-h4h5-9833-v2p4

  • GO-2024-3162 CVE-2024-7594 GHSA-jg74-mwgw-v6x3
  • GO-2024-3163 CVE-2024-47182
  • GO-2024-3164 CVE-2024-47003 GHSA-59hf-mpf8-pqjh
  • GO-2024-3166 CVE-2024-47534 GHSA-4f8r-qqr9-fq8j
  • GO-2024-3167 CVE-2024-9355 GHSA-3h3x-2hwv-hr52
  • GO-2024-3168 CVE-2024-8975 GHSA-chqx-36rm-rf8h
  • GO-2024-3169 CVE-2024-9407 GHSA-fhqq-8f65-5xfc
  • GO-2024-3170 CVE-2024-8996 GHSA-m5gv-m5f9-wgv4
  • GO-2024-3172 CVE-2024-33662 GHSA-9mjw-79r6-c9m8
  • GO-2024-3173 CVE-2024-7558 GHSA-mh98-763h-m9v4
  • GO-2024-3174 CVE-2024-8037 GHSA-8v4w-f4r9-7h6x
  • GO-2024-3175 CVE-2024-8038 GHSA-xwgj-vpm9-q2rq
  • GO-2024-3179 CVE-2024-47616 GHSA-r7rh-jww5-5fjr
  • GO-2024-3181 CVE-2024-9313 GHSA-x5q3-c8rm-w787
  • GO-2024-3182 GHSA-wpr2-j6gr-pjw9
  • GO-2024-3184 CVE-2024-36814 GHSA-9cp9-8gw2-8v7m
  • GO-2024-3185 CVE-2024-47832
  • GO-2024-3186 CVE-2024-9675 GHSA-586p-749j-fhwp
  • GO-2024-3188 CVE-2024-9312 GHSA-4gfw-wf7c-w6g2
  • GO-2024-3190 CVE-2024-47067 GHSA-8pph-gfhp-w226
  • GO-2024-3191 CVE-2024-9180 GHSA-rr8j-7w34-xp5j

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.5
    zypper in -t patch openSUSE-SLE-15.5-2024-3911=1
  • openSUSE Leap 15.6
    zypper in -t patch openSUSE-SLE-15.6-2024-3911=1
  • SUSE Package Hub 15 15-SP5
    zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-3911=1
  • SUSE Package Hub 15 15-SP6
    zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-3911=1

Package List:

  • openSUSE Leap 15.5 (noarch)
    • govulncheck-vulndb-0.0.20241030T212825-150000.1.9.1
  • openSUSE Leap 15.6 (noarch)
    • govulncheck-vulndb-0.0.20241030T212825-150000.1.9.1
  • SUSE Package Hub 15 15-SP5 (noarch)
    • govulncheck-vulndb-0.0.20241030T212825-150000.1.9.1
  • SUSE Package Hub 15 15-SP6 (noarch)
    • govulncheck-vulndb-0.0.20241030T212825-150000.1.9.1

References: