SLES 12

SLES 12 — libtcnative — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libtcnative — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:14014-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-8020 CVE-2017-15698 CVE-2018-8019 Upstream summary: Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced […]

Read more
SLES 12 — libxkbcommon0 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libxkbcommon0 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:232-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-15854 CVE-2018-15855 CVE-2018-15856 CVE-2018-15857 CVE-2018-15858 CVE-2018-15862 CVE-2018-15864 Upstream summary: Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash […]

Read more
SLES 12 — policycoreutils — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — policycoreutils — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 March 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0338-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-7545 CVE-2018-1063 Upstream summary: SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. Table of […]

Read more
SLES 12 — libseccomp2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libseccomp2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 March 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:742-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-9893 Upstream summary: libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able […]

Read more
SLES 12 — libpodofo0_9_2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpodofo0_9_2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 March 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3541-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8981 CVE-2017-6841 CVE-2017-6842 CVE-2017-6849 CVE-2017-8378 CVE-2019-10723 CVE-2018-12983 CVE-2019-20093  +12 more Upstream summary: Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers […]

Read more
SLES 12 — NetworkManager-vpnc — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — NetworkManager-vpnc — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 March 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:2297-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10900 Upstream summary: Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be […]

Read more
SLES 12 — haproxy — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — haproxy — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 March 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:3125-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-18277 CVE-2012-2391 CVE-2013-1912 CVE-2013-2175 CVE-2014-6269 CVE-2015-3281 Upstream summary: A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing […]

Read more
SLES 12 — python-azure-agent — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-azure-agent — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 February 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0603-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-0804 Upstream summary: An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure […]

Read more
SLES 12 — corosync — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — corosync — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 February 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1121-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1084 Upstream summary: corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
SLES 12 — perl-Archive-Zip — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-Archive-Zip — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 February 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:2385-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10860 Upstream summary: perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while […]

Read more
CHAT