SLES 12

SLES 12 — libgit2 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgit2 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 April 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0433-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2016-8568 CVE-2016-8569 CVE-2017-5338 CVE-2017-5339 CVE-2018-10887  +4 more Upstream summary: Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol […]

Read more
SLES 12 — rubygem-passenger — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — rubygem-passenger — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 March 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2337-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7519 CVE-2017-1000384 CVE-2017-16355 CVE-2018-12029 Upstream summary: agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone […]

Read more
SLES 12 — python-tablib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-tablib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 March 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2105-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-2810 Upstream summary: An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting […]

Read more
SLES 12 — librelp0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — librelp0 — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 10 March 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:0822-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1000140 Upstream summary: rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can […]

Read more
SLES 12 — libykcs11 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libykcs11 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 February 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1123-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-14779 CVE-2018-14780 Upstream summary: A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the […]

Read more
SLES 12 — binutils — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — binutils — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 February 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:723-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-7227 CVE-2017-7614 CVE-2017-8395 CVE-2017-8397 CVE-2017-9042 CVE-2014-8484 CVE-2014-8485 CVE-2014-8501  +12 more Upstream summary: GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer […]

Read more
SLES 12 — shotwell — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — shotwell — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 February 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:0637-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-1000024 Upstream summary: Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in […]

Read more
SLES 12 — libnl — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libnl — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3207-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-0386 Upstream summary: An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context […]

Read more
SLES 12 — libqxp — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libqxp — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 February 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1076-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-9432 CVE-2017-9433 CVE-2018-1055 CVE-2018-6871 Upstream summary: Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the […]

Read more
SLES 12 — libzmf — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libzmf — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 February 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1821-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8947 CVE-2016-2052 CVE-2016-10327 CVE-2017-7870 CVE-2017-7882 CVE-2017-8358 Upstream summary: hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or […]

Read more
CHAT