SLES 15

SLES 15 — checkbashisms — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — checkbashisms — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2012-2240 CVE-2012-2241 CVE-2012-3500 Upstream summary: scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands." Table of contents […]

Read more
SLES 15 — btrfsmaintenance — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — btrfsmaintenance — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2018-14722 Upstream summary: An issue was discovered in evaluate_auto_mountpoint in btrfsmaintenance-functions in btrfsmaintenance through 0.4.1. Code execution as root can occur via a specially crafted […]

Read more
SLES 15 — gv — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gv — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1329-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-3386 Upstream summary: The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces […]

Read more
SLES 15 — python2-pip — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-pip — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-FU-2021:2130-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-5123 CVE-2014-8991 CVE-2015-2296 Upstream summary: The mirroring support (-M, –use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers […]

Read more
SLES 15 — jasper — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — jasper — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0084-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9398 CVE-2016-9399 CVE-2017-5499 CVE-2017-5503 CVE-2017-5504 CVE-2017-5505 CVE-2018-20570 CVE-2018-20622  +7 more Upstream summary: The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to […]

Read more
SLES 15 — libstaroffice — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libstaroffice — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1076-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-9432 Upstream summary: Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the DatabaseName::read function in […]

Read more
SLES 15 — conntrackd — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — conntrackd — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1545-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-6496 Upstream summary: conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote […]

Read more
SLES 15 — libboost_regex_legacy — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libboost_regex_legacy — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2021:1414-1 (see also SUSE bugzilla) Related CVEs: CVE-2008-0171 Upstream summary: regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service […]

Read more
SLES 15 — perl-Config-IniFiles — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — perl-Config-IniFiles — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 November 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-2451 Upstream summary: The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via […]

Read more
SLES 15 — hyper-v — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — hyper-v — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2012:1673-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2669 CVE-2012-5532 Upstream summary: The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of […]

Read more
CHAT