SLES 12

SLES 12 — libwps — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libwps — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1728-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-0794 CVE-2016-0795 CVE-2018-16858 Upstream summary: The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly […]

Read more
SLES 12 — python-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 January 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:744-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-14853 CVE-2019-14859 Upstream summary: An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or […]

Read more
SLES 12 — bzip2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bzip2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 January 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:018 (see also SUSE bugzilla) Related CVEs: CVE-2010-0405 CVE-2019-12900 CVE-2016-3189 Upstream summary: Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a […]

Read more
SLES 12 — open-lldp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — open-lldp — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 January 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:3520-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10932 Upstream summary: lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an […]

Read more
SLES 12 — blktrace — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — blktrace — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 December 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0919-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10689 Upstream summary: blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function […]

Read more
SLES 12 — libwpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libwpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 November 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2931-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14226 CVE-2018-19208 Upstream summary: WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer […]

Read more
SLES 12 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 November 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:005 (see also SUSE bugzilla) Related CVEs: CVE-2011-0541 CVE-2015-3202 CVE-2018-10906 CVE-2009-3297 Upstream summary: fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount […]

Read more
SLES 12 — apache-pdfbox — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — apache-pdfbox — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 November 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:3318-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-11797 CVE-2016-2175 CVE-2018-8036 Upstream summary: In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long […]

Read more
SLES 12 — nmap — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — nmap — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 October 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1286-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-15173 Upstream summary: Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application […]

Read more
SLES 12 — smt — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — smt — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 13 October 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:2898-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-12472 CVE-2018-12470 CVE-2018-12471 CVE-2014-3566 Upstream summary: A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. […]

Read more
CHAT