SLES 12

SLES 12 — lftp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — lftp — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 October 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0642-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10916 Upstream summary: It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a […]

Read more
SLES 12 — npm4 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — npm4 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 5 October 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0117-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-12120 CVE-2016-7099 CVE-2016-7052 CVE-2016-5325 CVE-2017-11499 CVE-2017-14919 CVE-2017-15896 CVE-2018-12115  +12 more Upstream summary: Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any […]

Read more
SLES 12 — obs-service-tar — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — obs-service-tar — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 September 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2019:0880-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-12476 CVE-2018-12473 CVE-2018-12474 Upstream summary: Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over […]

Read more
SLES 12 — libgraphite2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgraphite2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 September 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:0779-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-1521 CVE-2016-1523 CVE-2016-1526 CVE-2018-7999 Upstream summary: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and […]

Read more
SLES 12 — yast2-multipath — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yast2-multipath — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 September 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:3231-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-17955 Upstream summary: In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection Table of […]

Read more
SLES 12 — vinagre — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — vinagre — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 September 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2234-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-2834 CVE-2017-2835 CVE-2018-0886 CVE-2018-8784 CVE-2018-8785 CVE-2018-8786 CVE-2018-8787 CVE-2018-8788  +6 more Upstream summary: An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. […]

Read more
SLES 12 — libvorbis0 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libvorbis0 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 July 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2008:012 (see also SUSE bugzilla) Related CVEs: CVE-2008-1420 CVE-2009-3379 CVE-2012-0444 CVE-2017-14160 CVE-2017-14632 CVE-2017-14633 CVE-2018-10392 CVE-2018-10393  +1 more Upstream summary: Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 […]

Read more
SLES 12 — opencc — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — opencc — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 July 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:4288-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-16982 Upstream summary: Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.cpp may have out-of-bounds […]

Read more
SLES 12 — nasm — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — nasm — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 July 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:14246-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14228 CVE-2017-17810 CVE-2017-10686 CVE-2017-17811 CVE-2017-17812 CVE-2017-17814 CVE-2017-17815 CVE-2017-17816  +6 more Upstream summary: In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the […]

Read more
SLES 12 — pam_yubico — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_yubico — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 June 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2018-9275 Upstream summary: In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the […]

Read more
CHAT