SLES 12

SLES 12 — ruby2.1-rubygem-yard — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ruby2.1-rubygem-yard — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 April 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1890-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-17042 Upstream summary: lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to […]

Read more
SLES 12 — php7 — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — php7 — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 April 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0534-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-5340 CVE-2016-10162 CVE-2016-7133 CVE-2016-7479 CVE-2016-7480 CVE-2016-9138 CVE-2016-9936 CVE-2017-11142  +6 more Upstream summary: Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that […]

Read more
SLES 12 — cvs — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cvs — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 31 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2012:0311-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-0804 CVE-2017-12836 Upstream summary: Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause […]

Read more
SLES 12 — ed — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ed — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:14005-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-5357 Upstream summary: regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an […]

Read more
SLES 12 — yodl — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yodl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1504-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-10375 Upstream summary: Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
SLES 12 — hexchat — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — hexchat — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:2872-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2087 Upstream summary: Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. […]

Read more
SLES 12 — SuSEfirewall2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — SuSEfirewall2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2923-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-15638 Upstream summary: The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 […]

Read more
SLES 12 — libgc1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgc1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-2673 CVE-2016-9427 Upstream summary: Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in […]

Read more
SLES 12 — libidn11 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libidn11 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14062 CVE-2015-8948 CVE-2016-6261 CVE-2016-6262 CVE-2016-6263 Upstream summary: Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a […]

Read more
SLES 12 — libXfont2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXfont2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-16611 Upstream summary: In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, […]

Read more
CHAT