SLES 12

SLES 12 — libapparmor1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libapparmor1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 January 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1151-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-6507 Upstream summary: An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd […]

Read more
SLES 12 — hostinfo — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — hostinfo — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 January 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1122-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-19636 CVE-2018-19637 CVE-2018-19639 CVE-2018-19640 CVE-2018-19638 Upstream summary: Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath […]

Read more
SLES 12 — libplist1 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libplist1 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 January 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1368-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-5209 CVE-2017-5834 CVE-2017-6440 CVE-2017-7982 CVE-2017-5545 CVE-2017-5835 CVE-2017-5836 Upstream summary: The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information […]

Read more
SLES 12 — libXcursor1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXcursor1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 December 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2003 CVE-2015-9262 CVE-2017-16612 Upstream summary: Integer overflow in X.org libXcursor 1.1.13 and earlier allows X servers to trigger allocation of insufficient memory and a buffer […]

Read more
SLES 12 — libkde4 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libkde4 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 December 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1335-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-8422 Upstream summary: KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a […]

Read more
SLES 12 — libgvnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgvnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 December 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:3125-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-5884 CVE-2017-5885 Upstream summary: gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the […]

Read more
SLES 12 — cpp48 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cpp48 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 November 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-5044 CVE-2017-11671 Upstream summary: Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application […]

Read more
SLES 12 — libbotan — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libbotan — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 November 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1222-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-9742 CVE-2015-5726 CVE-2015-5727 CVE-2015-7827 CVE-2016-2194 CVE-2016-2195 CVE-2016-9132 CVE-2017-14737  +2 more Upstream summary: The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly […]

Read more
SLES 12 — minicom — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — minicom — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 November 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1092-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-7467 Upstream summary: A buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could […]

Read more
SLES 12 — tboot — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — tboot — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 November 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:3090-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-16837 Upstream summary: Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users […]

Read more
CHAT