SLES 15

SLES 15 — pam_radius — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — pam_radius — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 January 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:1117-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-9542 Upstream summary: add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based […]

Read more
SLES 15 — log4j12 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — log4j12 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 January 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-5645 Upstream summary: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from […]

Read more
SLES 15 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:005 (see also SUSE bugzilla) Related CVEs: CVE-2011-0541 CVE-2015-3202 CVE-2018-10906 CVE-2009-3297 Upstream summary: fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount […]

Read more
SLES 15 — argyllcms — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — argyllcms — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-1616 Upstream summary: Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause […]

Read more
SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2010-2529 Upstream summary: Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of […]

Read more
SLES 15 — liboath0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — liboath0 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2013-7322 Upstream summary: usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which […]

Read more
SLES 15 — libcacard0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcacard0 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1058-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-6414 Upstream summary: Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of […]

Read more
SLES 15 — postgresql — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — postgresql — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:3107-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14798 Upstream summary: A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their […]

Read more
SLES 15 — perl-XML-Twig — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — perl-XML-Twig — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:2172-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9180 Upstream summary: perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless […]

Read more
SLES 15 — blktrace — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — blktrace — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0919-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10689 Upstream summary: blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function […]

Read more
CHAT