SLES 12

SLES 12 — python-cffi — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-cffi — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1458-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-23931 Upstream summary: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects […]

Read more
SLES 12 — sysstat — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — sysstat — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 December 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:0026-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-19725 CVE-2023-33204 CVE-2022-39377 CVE-2019-16167 CVE-2018-19416 CVE-2018-19517 Upstream summary: sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. Table of contents Symptom & Impact […]

Read more
SLES 12 — libXpm4 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXpm4 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 December 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:323-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-4883 CVE-2023-43788 CVE-2023-43789 CVE-2022-44617 CVE-2022-46285 CVE-2016-10164 Upstream summary: A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls […]

Read more
SLES 12 — python-tornado — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-tornado — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 November 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2913-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-28370 CVE-2014-9720 Upstream summary: Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary […]

Read more
SLES 12 — cpio — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cpio — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 November 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:283-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-38185 CVE-2023-7207 CVE-2019-14866 CVE-2014-9112 CVE-2016-2037 Upstream summary: GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a […]

Read more
SLES 12 — w3m — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — w3m — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 October 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0014-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-4255 CVE-2022-38223 CVE-2010-2074 CVE-2012-4929 CVE-2016-9434 CVE-2016-9435 CVE-2016-9436 CVE-2016-9437  +12 more Upstream summary: An out-of-bounds write issue has been discovered in the backspace handling of the […]

Read more
SLES 12 — xfig — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xfig — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 October 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1196-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-45920 CVE-2009-1962 CVE-2009-4227 Upstream summary: Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is […]

Read more
SLES 12 — libQt5Gui5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libQt5Gui5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 September 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:1567-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-24607 CVE-2020-0569 CVE-2020-24741 CVE-2023-33285 CVE-2018-19872 CVE-2018-19870 Upstream summary: Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver […]

Read more
SLES 12 — libva2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libva2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 September 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:1451-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-39929 Upstream summary: Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation […]

Read more
SLES 12 — slurm — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — slurm — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 September 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:1787-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-31215 CVE-2023-41914 CVE-2023-49936 CVE-2023-49937 CVE-2023-49933 CVE-2023-49938 Upstream summary: SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because […]

Read more
CHAT