SLES 12

SLES 12 — libplist3 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libplist3 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 October 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0872-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-10082 CVE-2017-6435 CVE-2017-6437 CVE-2017-6438 CVE-2017-6439 CVE-2017-6436 Upstream summary: A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml […]

Read more
SLES 12 — libdw1 — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libdw1 — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 October 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-0172 CVE-2014-9447 CVE-2017-7607 CVE-2017-7608 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613  +9 more Upstream summary: Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as […]

Read more
SLES 12 — rpcbind — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — rpcbind — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 October 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1306-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-8779 CVE-2015-7236 Upstream summary: rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data […]

Read more
SLES 12 — dovecot — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dovecot — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 August 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1250-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-2669 Upstream summary: Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the […]

Read more
SLES 12 — yubikey-manager — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yubikey-manager — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2017-15631 Upstream summary: TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file. Table […]

Read more
SLES 12 — libopus0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libopus0 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0436-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-0381 Upstream summary: An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its […]

Read more
SLES 12 — libzip2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libzip2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:009 (see also SUSE bugzilla) Related CVEs: CVE-2011-0421 CVE-2012-1162 CVE-2012-1163 CVE-2015-2331 CVE-2017-14107 Upstream summary: The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a […]

Read more
SLES 12 — libquicktime0 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libquicktime0 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0610-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2399 CVE-2017-9122 CVE-2017-9123 CVE-2017-9124 CVE-2017-9125 CVE-2017-9126 CVE-2017-9127 CVE-2017-9128 Upstream summary: Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to […]

Read more
SLES 12 — lhasa — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — lhasa — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1091-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2347 Upstream summary: Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted […]

Read more
SLES 12 — ipsec-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ipsec-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1367-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-4047 CVE-2016-10396 Upstream summary: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via […]

Read more
CHAT