Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2022-24741: nextcloud: High memory usage for generating preview of broken image | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Distribution | Reporter: | Thomas Leroy <thomas.leroy> |
Component: | Security | Assignee: | Eric Schirra <ecsos> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P4 - Low | ||
Version: | Leap 15.4 | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/325660/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Thomas Leroy
2022-03-10 08:25:20 UTC
Affected: - openSUSE:Backports:SLE-15-SP3 v20.0.7 - openSUSE:Backports:SLE-15-SP3:Update v20.0.14 - openSUSE:Backports:SLE-15-SP4 v23.0.0 Can't do an mr! osc mr -m "Security update see boo#1196905, boo#1196908 and boo#1196952" rise up following error: Using target project 'openSUSE:Maintenance' Server returned an error: HTTP Error 400: Bad Request Maintenance incident request contains release target project openSUSE:Backports:SLE-15-SP4 with invalid project kind "standard" (should be "maintenance_release") for package nextcloud.openSUSE_Backports_SLE-15-SP4 I have generate first the dirs with following command, wich i use for several mr in the past: osc mbranch nextcloud This is an autogenerated message for OBS integration: This bug (1196952) was mentioned in https://build.opensuse.org/request/show/962687 Backports:SLE-12 / nextcloud https://build.opensuse.org/request/show/962688 Backports:SLE-15-SP3 / nextcloud https://build.opensuse.org/request/show/962689 Backports:SLE-15-SP4 / nextcloud openSUSE-SU-2022:0089-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1196905,1196908,1196952 CVE References: CVE-2021-41239,CVE-2021-41241,CVE-2021-41741 JIRA References: Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): nextcloud-21.0.9-37.1 openSUSE-SU-2022:0098-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1196905,1196908,1196952 CVE References: CVE-2021-41239,CVE-2021-41241,CVE-2021-41741 JIRA References: Sources used: openSUSE Backports SLE-15-SP3 (src): nextcloud-21.0.9-bp153.2.12.1 Leap 15.4 has version 23.0.2 |