SLES 12

SLES 12 — liblasso3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — liblasso3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 6 July 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:21452 (see also SUSE bugzilla) Related CVEs: CVE-2025-47151 CVE-2025-46404 CVE-2025-46705 CVE-2025-46784 CVE-2021-28091 Upstream summary: A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted […]

Read more
SLES 12 — libgsf — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgsf — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3770-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-36474 CVE-2024-42415 CVE-2016-9888 Upstream summary: An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File […]

Read more
SLES 12 — gnuplot — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gnuplot — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:01805-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-31178 CVE-2025-31181 CVE-2025-3359 CVE-2025-31179 CVE-2020-25969 CVE-2017-9670 CVE-2018-19490 CVE-2018-19491  +1 more Upstream summary: A flaw was found in gnuplot. The GetAnnotateString() function may lead to a […]

Read more
SLES 12 — python-setuptools — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-setuptools — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:10407 (see also SUSE bugzilla) Related CVEs: CVE-2025-47273 CVE-2024-6345 CVE-2022-40897 CVE-2013-7440 Upstream summary: setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal […]

Read more
SLES 12 — apache-commons-beanutils — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — apache-commons-beanutils — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 27 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02056-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-4852 CVE-2025-48734 CVE-2014-3540 CVE-2019-10086 CVE-2014-0114 Upstream summary: The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute […]

Read more
SLES 12 — zabbix-agent — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — zabbix-agent — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3029-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-29450 CVE-2021-27927 CVE-2024-42333 CVE-2024-22119 CVE-2022-43515 CVE-2022-35230 CVE-2022-24349 CVE-2013-7484  +7 more Upstream summary: JavaScript pre-processing can be used by the attacker to gain access to the […]

Read more
SLES 12 — php74 — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — php74 — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10952 (see also SUSE bugzilla) Related CVEs: CVE-2023-3823 CVE-2023-3824 CVE-2023-0568 CVE-2023-0662 CVE-2022-37454 CVE-2021-21708 CVE-2024-8927 CVE-2024-9026  +10 more Upstream summary: In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 […]

Read more
SLES 12 — npm16 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — npm16 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1301-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-27983 CVE-2024-22019 CVE-2023-32067 CVE-2023-24807 CVE-2023-23919 CVE-2022-35255 CVE-2024-27982 CVE-2024-30261  +12 more Upstream summary: An attacker can make the Node.js HTTP/2 server completely unavailable by sending a […]

Read more
SLES 12 — npm18 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — npm18 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:3919-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-7783 CVE-2024-21892 CVE-2025-22150 CVE-2025-23085 CVE-2024-21538 CVE-2024-22020 CVE-2024-36138 CVE-2024-27980 Upstream summary: Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability […]

Read more
SLES 12 — socat — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — socat — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 June 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:0726-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-1379 CVE-2024-54661 CVE-2013-3571 CVE-2014-0019 Upstream summary: The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service […]

Read more
CHAT