Linux

SLES 15 — librabbitmq4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — librabbitmq4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2823-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-35789 CVE-2019-18609 Upstream summary: An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered […]

Read more
SLES 12 — vorbis-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — vorbis-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4218-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-43361 CVE-2008-1686 CVE-2014-9638 CVE-2014-9639 CVE-2014-9640 CVE-2015-6749 Upstream summary: Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a […]

Read more
openSUSE Leap 15.5 — less — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — less — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1534-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-32487 CVE-2022-48624 Upstream summary: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is […]

Read more
openSUSE Leap 15.5 — MozillaThunderbird — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — MozillaThunderbird — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:6683 (see also SUSE bugzilla) Related CVEs: CVE-2024-8394 CVE-2024-1936 CVE-2023-50761 CVE-2023-50762 CVE-2023-4573 CVE-2023-3417 CVE-2024-50336 CVE-2024-11159 Upstream summary: When aborting the verification of an OTR chat session, an attacker could have caused […]

Read more
openSUSE Leap 15.5 — grafana — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — grafana — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2514-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-3128 CVE-2023-2801 CVE-2022-31097 CVE-2022-31107 CVE-2023-6152 CVE-2023-2183 CVE-2022-35957 CVE-2022-36062  +2 more Upstream summary: Grafana is validating Azure AD accounts based on the email claim. On […]

Read more
Debian 12 — node-mixin-deep — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-mixin-deep — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-3719 CVE-2019-10746 Upstream summary: mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of […]

Read more
Amazon Linux 2 — perl-App-cpanminus — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — perl-App-cpanminus — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2697 Related CVEs: CVE-2024-45321 CVE-2020-16154 Upstream summary: The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers. (CVE-2024-45321) Table of contents Symptom […]

Read more
Debian 12 — rbdoom3bfg — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rbdoom3bfg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-15007 Upstream summary: A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of […]

Read more
Debian 12 — mgetty — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mgetty — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-1391 CVE-2002-1392 CVE-2003-0516 CVE-2003-0517 CVE-2008-4936 CVE-2018-16741 CVE-2018-16742 CVE-2018-16743  +4 more Upstream summary: Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of […]

Read more
Oracle Linux 9 — tigervnc — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 9

Oracle Linux 9 — tigervnc — vulnerability — patch and remediation guide (ELSA-2023-0622)

🟠 High   ⏱ 15–60 min  Last verified: 16 April 2024 Affected versions: Oracle Linux 9 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-0622 Related CVEs: CVE-2023-0494 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
CHAT