SLES 12

SLES 12 — perl-XML-Twig — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-XML-Twig — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 September 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:2172-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9180 Upstream summary: perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless […]

Read more
SLES 12 — fontconfig — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — fontconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 September 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:2186-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-5384 Upstream summary: fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks […]

Read more
SLES 12 — ruby2.1-rubygem-archive-tar-minitar — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ruby2.1-rubygem-archive-tar-minitar — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 July 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:0115-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-10173 Upstream summary: Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files […]

Read more
SLES 12 — at — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — at — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 June 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:723-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8079 CVE-2016-6354 Upstream summary: qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
SLES 12 — dosfstools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dosfstools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 June 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:2145-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8872 CVE-2016-4804 Upstream summary: The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial […]

Read more
SLES 12 — clamsap — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — clamsap — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 June 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:0805-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-2278 CVE-2015-2282 Upstream summary: The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server […]

Read more
SLES 12 — squidGuard — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — squidGuard — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 June 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:014 (see also SUSE bugzilla) Related CVEs: CVE-2009-3700 CVE-2009-3826 CVE-2015-8936 Upstream summary: Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang […]

Read more
SLES 12 — update-alternatives — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — update-alternatives — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 June 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1096-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-0860 CVE-2015-0840 Upstream summary: Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before […]

Read more
SLES 12 — libgme0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgme0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 May 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:3250-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 Upstream summary: Stack-based buffer overflow in game-music-emu before 0.6.1. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
SLES 12 — libstorage5 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libstorage5 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:2189-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-5746 Upstream summary: libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users […]

Read more
CHAT