SLES 12

SLES 12 — m4 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — m4 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 December 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1329-1 (see also SUSE bugzilla) Related CVEs: CVE-2009-4029 Upstream summary: The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution […]

Read more
SLES 12 — libXvMC1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXvMC1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 December 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1990 CVE-2013-1999 Upstream summary: Multiple integer overflows in X.org libXvMC 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer […]

Read more
SLES 12 — davfs2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — davfs2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 December 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2014-4362 Upstream summary: The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID […]

Read more
SLES 12 — yast2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yast2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 December 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-3177 Upstream summary: The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network […]

Read more
SLES 12 — libserf — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libserf — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-3504 Upstream summary: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL […]

Read more
SLES 12 — libyaml — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libyaml — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0403-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-6393 CVE-2014-2525 CVE-2014-9130 Upstream summary: The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a […]

Read more
SLES 12 — pam_krb5 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_krb5 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2008:027 (see also SUSE bugzilla) Related CVEs: CVE-2008-3825 CVE-2009-1384 Upstream summary: pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when […]

Read more
SLES 12 — openvas-manager — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — openvas-manager — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-9220 Upstream summary: SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the […]

Read more
SLES 12 — FastCGI — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — FastCGI — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-2766 Upstream summary: The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request […]

Read more
SLES 12 — python-cinder — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-cinder — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1467-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-3641 Upstream summary: The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from […]

Read more
CHAT