SLES 12

SLES 12 — perl-Config-IniFiles — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-Config-IniFiles — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-2451 Upstream summary: The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via […]

Read more
SLES 12 — python-xml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-xml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0576-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-1912 CVE-2011-1521 Upstream summary: Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows […]

Read more
SLES 12 — xlockmore — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xlockmore — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-4143 Upstream summary: The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL value is returned upon […]

Read more
SLES 12 — xinetd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xinetd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0466-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-0862 CVE-2013-4342 Upstream summary: builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled […]

Read more
SLES 12 — pam_radius — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_radius — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:1117-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-9542 Upstream summary: add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based […]

Read more
SLES 12 — gpgme — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gpgme — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1073-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-3564 Upstream summary: Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to […]

Read more
SLES 12 — libimobiledevice6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libimobiledevice6 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-2142 Upstream summary: userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack […]

Read more
SLES 12 — libgssglue1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgssglue1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-2709 Upstream summary: libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary […]

Read more
SLES 12 — python-neutron — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-neutron — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0018-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-6414 CVE-2014-7821 CVE-2014-3555 CVE-2014-8153 Upstream summary: OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default […]

Read more
SLES 12 — mozilla-nspr — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — mozilla-nspr — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 January 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1680-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-4500 CVE-2015-4501 CVE-2015-4506 CVE-2015-4509 CVE-2015-4511 CVE-2015-4517 CVE-2015-4519 CVE-2015-4520  +8 more Upstream summary: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and […]

Read more
CHAT