openSUSE

openSUSE Tumbleweed — exiftool — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — exiftool — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2022-23935 Upstream summary: lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /|$/ check, leading to command injection. Table of contents Symptom & Impact Environment […]

Read more
openSUSE Tumbleweed — python38-mistune — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python38-mistune — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:14637-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-34749 Upstream summary: In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking […]

Read more
openSUSE Tumbleweed — HyperKitty-web — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — HyperKitty-web — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2021-25322 CVE-2021-33038 CVE-2021-35057 Upstream summary: A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges […]

Read more
openSUSE Tumbleweed — go1.14 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — go1.14 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2020:2047-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-28362 CVE-2020-28366 CVE-2020-28367 CVE-2021-3115 CVE-2020-24553 CVE-2021-3114 Upstream summary: Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. Table of contents Symptom & Impact […]

Read more
openSUSE Tumbleweed — python36-Pillow — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python36-Pillow — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2021:1134-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-25289 CVE-2020-35653 CVE-2020-35654 CVE-2020-35655 CVE-2021-23437 CVE-2021-25290 CVE-2021-25291 CVE-2021-25292  +3 more Upstream summary: An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer […]

Read more
openSUSE Tumbleweed — mozjs78 — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — mozjs78 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2021:1184-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-29984 Upstream summary: Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led […]

Read more
openSUSE Tumbleweed — quagga — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — quagga — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2018:0473-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-5379 CVE-2021-44038 CVE-2018-5381 CVE-2006-2223 CVE-2007-1995 CVE-2013-2236 CVE-2016-1245 CVE-2016-2342  +11 more Upstream summary: The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when […]

Read more
openSUSE Tumbleweed — atftp — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — atftp — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1091-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-11365 CVE-2020-6097 CVE-2021-41054 Upstream summary: An issue was discovered in atftpd in atftp 0.7.1. A remote attacker may send a crafted packet triggering a stack-based […]

Read more
openSUSE Tumbleweed — wp-cli — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — wp-cli — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2021-29504 Upstream summary: WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI version 0.12.0 and later allows remote attackers able to […]

Read more
openSUSE Tumbleweed — ruby2.7-rubygem-kramdown — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — ruby2.7-rubygem-kramdown — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:15119-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-28834 CVE-2020-14001 Upstream summary: Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Table of […]

Read more
CHAT