SLES 12

SLES 12 — libopenjp2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libopenjp2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 May 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1129-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-27823 CVE-2020-8112 CVE-2024-56826 CVE-2020-27824 CVE-2020-27842 CVE-2020-27843 CVE-2020-27845 CVE-2016-1924  +12 more Upstream summary: A flaw was found in OpenJPEG's encoder. This flaw allows an attacker to […]

Read more
SLES 12 — OpenIPMI — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — OpenIPMI — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8037 (see also SUSE bugzilla) Related CVEs: CVE-2024-42934 Upstream summary: OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with […]

Read more
SLES 12 — python-dnspython — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-dnspython — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 May 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9423 (see also SUSE bugzilla) Related CVEs: CVE-2023-29483 Upstream summary: eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an […]

Read more
SLES 12 — gimp — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gimp — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:0746 (see also SUSE bugzilla) Related CVEs: CVE-2023-44442 CVE-2023-44444 CVE-2022-32990 CVE-2022-30067 CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787  +11 more Upstream summary: GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability […]

Read more
SLES 12 — libraw9 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libraw9 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 30 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2300-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8367 CVE-2020-22628 CVE-2023-1729 CVE-2021-32142 CVE-2017-6889 CVE-2020-15503 CVE-2013-2126 CVE-2013-2127  +12 more Upstream summary: The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors […]

Read more
SLES 12 — libmicrohttpd10 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmicrohttpd10 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:1686-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-27371 CVE-2013-7038 CVE-2013-7039 Upstream summary: GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the […]

Read more
SLES 12 — vorbis-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — vorbis-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4218-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-43361 CVE-2008-1686 CVE-2014-9638 CVE-2014-9639 CVE-2014-9640 CVE-2015-6749 Upstream summary: Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a […]

Read more
SLES 12 — libhdf5-gnu-hpc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libhdf5-gnu-hpc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0538-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-4332 CVE-2018-13867 CVE-2018-17439 CVE-2021-37501 CVE-2021-45830 CVE-2021-45833 CVE-2021-46242 CVE-2024-29158  +12 more Upstream summary: The library's failure to check if certain message types support a particular flag, […]

Read more
SLES 12 — kgraft-patch — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kgraft-patch — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:0263-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-50756 CVE-2023-6546 CVE-2022-0886 CVE-2021-3573 CVE-2015-1421 CVE-2015-4700 CVE-2015-8019 CVE-2017-17053  +2 more Upstream summary: In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix mempool […]

Read more
SLES 12 — postgresql-jdbc — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — postgresql-jdbc — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0769-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-1597 CVE-2022-31197 CVE-2022-41946 CVE-2020-13692 Upstream summary: pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. […]

Read more
CHAT