SLES 12

SLES 12 — kernel-azure — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kernel-azure — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1527-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4343 Upstream summary: Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and […]

Read more
SLES 12 — libsmi — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libsmi — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:001 (see also SUSE bugzilla) Related CVEs: CVE-2010-2891 Upstream summary: Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier […]

Read more
SLES 12 — id3lib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — id3lib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2007:019 (see also SUSE bugzilla) Related CVEs: CVE-2007-4460 Upstream summary: The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on […]

Read more
SLES 12 — python-python-memcached — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-python-memcached — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1890-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-3221 CVE-2015-3241 CVE-2015-3280 CVE-2015-5240 CVE-2015-7713 Upstream summary: OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote […]

Read more
SLES 12 — dstat — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dstat — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2009-3894 Upstream summary: Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working […]

Read more
SLES 12 — argyllcms — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — argyllcms — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-1616 Upstream summary: Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause […]

Read more
SLES 12 — guestfsd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — guestfsd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1626-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4419 CVE-2013-2124 Upstream summary: The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the –remote or –listen option, does not properly check the […]

Read more
SLES 12 — flash-player — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — flash-player — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 29 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1211-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-0578 CVE-2015-3114 CVE-2015-3115 CVE-2015-3116 CVE-2015-3117 CVE-2015-3118 CVE-2015-3119 CVE-2015-3120  +12 more Upstream summary: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows […]

Read more
SLES 12 — perl-Net-Server — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-Net-Server — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0746-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1841 Upstream summary: Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address, which might allow […]

Read more
SLES 12 — fastjar — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — fastjar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:2635-1 (see also SUSE bugzilla) Related CVEs: CVE-2010-2322 Upstream summary: Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files […]

Read more
CHAT