openSUSE

openSUSE Tumbleweed — dom4j — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — dom4j — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2020:0719-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-10683 CVE-2018-1000632 Upstream summary: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, […]

Read more
openSUSE Tumbleweed — telegraf — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — telegraf — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2020-26160 Upstream summary: jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type assertion […]

Read more
openSUSE Tumbleweed — phpMyAdmin — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — phpMyAdmin — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2020:1675-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-26935 CVE-2005-2869 CVE-2006-1804 CVE-2015-8980 CVE-2016-9849 CVE-2016-9865 CVE-2018-12581 CVE-2018-15605  +12 more Upstream summary: An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before […]

Read more
openSUSE Tumbleweed — ant — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — ant — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:712-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-36373 CVE-2021-36374 CVE-2013-1571 CVE-2018-10886 CVE-2020-11979 CVE-2020-1945 Upstream summary: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large […]

Read more
openSUSE Tumbleweed — sddm — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — sddm — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-7271 CVE-2014-7272 CVE-2015-0856 CVE-2018-14345 CVE-2020-28049 Upstream summary: Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. […]

Read more
openSUSE Tumbleweed — crawl — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — crawl — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2020:0549-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-11722 Upstream summary: Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in […]

Read more
openSUSE Tumbleweed — polkit — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — polkit — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2022:0190-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-4034 CVE-2021-3560 CVE-2010-0750 CVE-2011-1485 CVE-2015-3255 CVE-2015-3256 CVE-2018-19788 CVE-2019-6133  +4 more Upstream summary: A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec […]

Read more
openSUSE Tumbleweed — libonig5 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libonig5 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2022:1093-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-19203 CVE-2019-19204 CVE-2019-19246 CVE-2019-13224 CVE-2019-13225 CVE-2019-19012 CVE-2020-26159 Upstream summary: An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, […]

Read more
openSUSE Tumbleweed — libvirt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libvirt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2022:0021-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-4147 CVE-2013-4296 CVE-2017-1000256 CVE-2019-10132 CVE-2019-10161 CVE-2019-10166 CVE-2019-10167 CVE-2019-10168  +12 more Upstream summary: A flaw was found in the libvirt libxl driver. A malicious guest could […]

Read more
openSUSE Tumbleweed — okular — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — okular — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2018:2727-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1000801 CVE-2020-9359 Upstream summary: okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(…)" in "core/document.cpp" that can result in Arbitrary file […]

Read more
CHAT