SLES 12

SLES 12 — libapr1 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libapr1 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 August 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3428-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-49582 CVE-2011-0419 CVE-2017-12613 CVE-2011-1928 Upstream summary: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to […]

Read more
SLES 12 — python-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 30 August 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2561-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-33733 CVE-2019-19450 CVE-2019-17626 CVE-2020-28463 Upstream summary: Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. Table of contents […]

Read more
SLES 12 — dbus — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dbus — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 August 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:263-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-35512 CVE-2012-3524 CVE-2023-34969 CVE-2022-42011 CVE-2022-42012 CVE-2019-12749 CVE-2020-12049 CVE-2010-1172  +12 more Upstream summary: A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable […]

Read more
SLES 12 — cpp7 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cpp7 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 August 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3021-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-4039 CVE-2019-14250 CVE-2019-15847 CVE-2020-13844 Upstream summary: **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing […]

Read more
SLES 12 — mdadm — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — mdadm — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 August 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3691-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-28736 CVE-2023-28938 Upstream summary: Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of […]

Read more
SLES 12 — bluez — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bluez — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 August 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9413 (see also SUSE bugzilla) Related CVEs: CVE-2023-27349 CVE-2022-39176 CVE-2019-8921 CVE-2019-8922 CVE-2023-45866 CVE-2021-41229 CVE-2022-39177 CVE-2020-0556  +12 more Upstream summary: BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. […]

Read more
SLES 12 — texlive — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — texlive — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 August 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:3033-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-17407 CVE-2020-8016 CVE-2020-8017 CVE-2023-46048 Upstream summary: An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in […]

Read more
SLES 12 — gawk — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gawk — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2768-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-4156 Upstream summary: A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could […]

Read more
SLES 12 — mdds — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — mdds — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 July 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4496-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-1183 Upstream summary: A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command […]

Read more
SLES 12 — sendmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — sendmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 July 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3898-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-31256 CVE-2023-51765 Upstream summary: A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE […]

Read more
CHAT