SLES 12

SLES 12 — libssh2 — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libssh2 — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:4230-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-48795 CVE-2020-22218 CVE-2019-17498 CVE-2015-1782 CVE-2016-0787 CVE-2019-3855 CVE-2019-3856 CVE-2019-3857  +6 more Upstream summary: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 […]

Read more
SLES 12 — qemu — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — qemu — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9136 (see also SUSE bugzilla) Related CVEs: CVE-2024-7409 CVE-2021-3750 CVE-2023-3354 CVE-2023-3180 CVE-2023-2861 CVE-2023-1544 CVE-2021-3929 CVE-2021-4206  +12 more Upstream summary: A flaw was found in the QEMU NBD Server. This vulnerability allows a […]

Read more
SLES 12 — liblouis9 — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — liblouis9 — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 March 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:1771-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-26767 CVE-2023-26768 CVE-2023-26769 CVE-2017-13738 CVE-2017-13739 CVE-2017-13740 CVE-2017-13741 CVE-2017-13743  +8 more Upstream summary: Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause […]

Read more
SLES 12 — python-configobj — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-configobj — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 March 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2023:602-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-26112 Upstream summary: All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** […]

Read more
SLES 12 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 February 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9243 (see also SUSE bugzilla) Related CVEs: CVE-2023-51764 CVE-2023-32182 Upstream summary: Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). […]

Read more
SLES 12 — libslurm39 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libslurm39 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 February 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0280-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-49935 Upstream summary: An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. […]

Read more
SLES 12 — opensc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — opensc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 February 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:3582-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-42781 CVE-2021-42782 CVE-2023-5992 CVE-2023-40661 CVE-2023-2977 CVE-2019-15945 CVE-2019-15946 CVE-2019-19479  +12 more Upstream summary: Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c […]

Read more
SLES 12 — libatk — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libatk — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 February 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-FU-2023:3413-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-0950 CVE-2023-2255 Upstream summary: Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a […]

Read more
SLES 12 — libgcrypt20 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgcrypt20 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:254-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-33560 CVE-2024-2236 CVE-2013-4242 CVE-2014-3591 CVE-2015-0837 CVE-2015-7511 CVE-2016-6313 CVE-2017-9526  +2 more Upstream summary: Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks […]

Read more
CHAT