IT, Cloud & DevOps Blog

SLES 12 — rtkit — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — rtkit — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-4326 Upstream summary: RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended […]

Read more
SLES 12 — libgnomesu — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgnomesu — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-1946 Upstream summary: gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid […]

Read more
SLES 12 — cracklib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cracklib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-6318 Upstream summary: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) […]

Read more
SLES 12 — telepathy-idle — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — telepathy-idle — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1364-1 (see also SUSE bugzilla) Related CVEs: CVE-2007-6746 Upstream summary: telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain […]

Read more
SLES 12 — libvdpau1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libvdpau1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1892-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 Upstream summary: libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, […]

Read more
CHAT