September 2024 - Page 92 of 94

openSUSE Tumbleweed — python310-python-jose — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python310-python-jose — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2024:0118-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-33663 CVE-2024-33664 Upstream summary: python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. Table of […]

Read more
openSUSE Tumbleweed — libvte — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libvte — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2151-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-37535 Upstream summary: GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a […]

Read more
openSUSE Tumbleweed — orthanc-gdcm — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — orthanc-gdcm — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2024:0167-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-22373 CVE-2024-22391 CVE-2024-25569 Upstream summary: An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file […]

Read more
NetBSD 9.4 — vim — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — vim — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2007-2438 CVE-2007-2953 CVE-2008-2712 CVE-2008-4677 CVE-2019-20079 CVE-2019-20807 CVE-2021-3796 CVE-2021-3974  +12 more Upstream summary: pkgsrc audit-packages flagged vim<6.3.045 for vulnerability class 'local-code-execution'. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1138 Table of contents Symptom & Impact Environment […]

Read more
Alpine Linux 3.19 — py3-pygments — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux 3.19

Alpine Linux 3.19 — py3-pygments — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.19 / fixed in 2.7.4-r0 📖 ~4 min read  •  Source: Alpine secdb entry — py3-pygments 2.7.4-r0 Related CVEs: CVE-2021-20270 Upstream summary: Alpine main repository for vv3.19 ships py3-pygments 2.7.4-r0 which addresses CVE-2021-20270. Table of contents Symptom & Impact Environment […]

Read more
openSUSE Leap 15.6 — OpenIPMI — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — OpenIPMI — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2024:14373-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-42934 Upstream summary: OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or […]

Read more
Windows Server 2016 — KB5037040 — security update — patch and remediation guide — diagnosis and fix on Windows Server 2016

Windows Server 2016 — KB5037040 — security update — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Windows Server 2016 📖 ~4 min read  •  Source: Microsoft KB5037040 • MSRC update-guide entry Related CVEs: CVE-2024-21409 Affected components: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2016 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
openSUSE Leap 15.6 — python3-pytest-django — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — python3-pytest-django — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2021:0322-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-25626 Upstream summary: A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django […]

Read more
Alpine Linux 3.18 — nss — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.18

Alpine Linux 3.18 — nss — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.18 / fixed in 3.76.1-r0 📖 ~4 min read  •  Source: Alpine secdb entry — nss 3.76.1-r0 Related CVEs: CVE-2022-1097 CVE-2021-43527 CVE-2020-25648 CVE-2020-12400 CVE-2020-12401 CVE-2020-12403 CVE-2020-6829 CVE-2020-12402  +4 more Upstream summary: Alpine community repository for vv3.18 ships nss 3.76.1-r0 which […]

Read more
openSUSE Leap 15.5 — libQt5Gui5 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — libQt5Gui5 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:4647 (see also SUSE bugzilla) Related CVEs: CVE-2024-39936 CVE-2023-24607 CVE-2023-32763 CVE-2023-45935 CVE-2023-51714 CVE-2023-37369 CVE-2023-32762 CVE-2023-33285  +2 more Upstream summary: An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before […]

Read more
CHAT