SLES 15

SLES 15 — pcsc-lite — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — pcsc-lite — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:015 (see also SUSE bugzilla) Related CVEs: CVE-2010-0407 CVE-2010-4531 CVE-2016-10109 Upstream summary: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite […]

Read more
SLES 15 — ibus — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ibus — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2387-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-14822 Upstream summary: A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to […]

Read more
SLES 15 — newt — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — newt — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2009:017 (see also SUSE bugzilla) Related CVEs: CVE-2009-2905 Upstream summary: Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) […]

Read more
SLES 15 — lftp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — lftp — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0642-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10916 Upstream summary: It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a […]

Read more
SLES 15 — ibus-pinyin — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ibus-pinyin — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-4509 Upstream summary: The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does […]

Read more
SLES 15 — libxcb1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libxcb1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1096-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2064 Upstream summary: Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via […]

Read more
SLES 15 — tboot — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tboot — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:3090-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-16837 Upstream summary: Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users […]

Read more
SLES 15 — icedtea-web — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — icedtea-web — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 February 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2033-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-10181 CVE-2019-10185 CVE-2013-4349 CVE-2019-10182 CVE-2011-2513 CVE-2011-2514 CVE-2011-3377 CVE-2012-3422  +6 more Upstream summary: It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 […]

Read more
SLES 15 — libjansson4 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libjansson4 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 January 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0467-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-6401 Upstream summary: Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a […]

Read more
SLES 15 — jython — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — jython — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-2027 Upstream summary: Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended […]

Read more
CHAT