SLES 12

SLES 12 — osc — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — osc — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 July 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2067-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-3685 CVE-2010-4226 CVE-2017-14804 CVE-2017-9274 CVE-2024-22034 CVE-2019-3681 CVE-2015-0778 CVE-2012-1095 Upstream summary: Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the […]

Read more
SLES 12 — libz1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libz1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 July 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1863-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-37434 CVE-2018-25032 CVE-2023-45853 Upstream summary: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header […]

Read more
SLES 12 — libgstapp — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgstapp — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:11123 (see also SUSE bugzilla) Related CVEs: CVE-2024-47538 CVE-2024-47607 CVE-2024-47615 CVE-2024-47541 CVE-2024-47542 CVE-2024-47613 CVE-2024-47835 Upstream summary: GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected […]

Read more
SLES 12 — procps — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — procps — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1122 CVE-2018-1123 CVE-2018-1124 CVE-2018-1125 CVE-2018-1126 CVE-2023-4016 Upstream summary: procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs […]

Read more
SLES 12 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 17 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2401-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-9855 CVE-2024-5261 CVE-2024-3044 CVE-2023-6185 CVE-2023-6186 CVE-2022-26305 CVE-2019-9852 CVE-2019-9854  +12 more Upstream summary: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which […]

Read more
SLES 12 — python-idna — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-idna — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8365 (see also SUSE bugzilla) Related CVEs: CVE-2024-3651 Upstream summary: A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's […]

Read more
SLES 12 — ovmf — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ovmf — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 13 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0579-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-12178 CVE-2023-45232 CVE-2023-45233 CVE-2023-45235 CVE-2022-36765 CVE-2023-45230 CVE-2023-45234 CVE-2021-38578  +12 more Upstream summary: Buffer overflow in network stack for EDK II may allow unprivileged user to […]

Read more
SLES 12 — cloud-init — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cloud-init — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2021:6-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-8631 CVE-2020-8632 CVE-2021-3429 CVE-2023-1786 CVE-2019-0816 Upstream summary: cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to […]

Read more
SLES 12 — unrar — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — unrar — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1975-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-33899 CVE-2022-30333 CVE-2017-12938 CVE-2017-12940 CVE-2017-12941 CVE-2017-12942 CVE-2017-20006 CVE-2012-6706 Upstream summary: RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen […]

Read more
SLES 12 — drbd — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — drbd — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2960-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-1989 CVE-2023-1990 CVE-2023-2162 CVE-2023-1390 CVE-2023-28464 CVE-2023-28772 CVE-2023-1118 CVE-2023-0590  +12 more Upstream summary: A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. […]

Read more
CHAT