SLES 15

SLES 15 — radvd — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — radvd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-3602 Upstream summary: Directory traversal vulnerability in device-linux.c in the router advertisement daemon (radvd) before 1.8.2 allows local users to overwrite arbitrary files, and remote […]

Read more
SLES 15 — systemtap — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — systemtap — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:010 (see also SUSE bugzilla) Related CVEs: CVE-2009-4273 CVE-2010-0412 CVE-2009-2911 CVE-2010-0411 Upstream summary: stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments […]

Read more
SLES 15 — libwmf — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libwmf — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2006:019 (see also SUSE bugzilla) Related CVEs: CVE-2006-3376 CVE-2016-9011 CVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696 Upstream summary: Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, […]

Read more
SLES 15 — mariadb104 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — mariadb104 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2023:3956-1 (see also SUSE bugzilla) Related CVEs: CVE-2006-0903 CVE-2006-4227 CVE-2007-5969 CVE-2007-6304 CVE-2008-2079 CVE-2006-4226 CVE-2007-6303 Upstream summary: MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain […]

Read more
SLES 15 — libXRes1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libXRes1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1988 Upstream summary: Multiple integer overflows in X.org libXRes 1.0.6 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
SLES 15 — yast2-devtools — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — yast2-devtools — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1890-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-17042 Upstream summary: lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to […]

Read more
SLES 15 — libavutil55 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libavutil55 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 9 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-16840 CVE-2017-11665 CVE-2015-8216 CVE-2015-8217 CVE-2015-8218 CVE-2015-8219 CVE-2015-8363 CVE-2015-8364  +12 more Upstream summary: The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers […]

Read more
SLES 15 — libwebp7 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libwebp7 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2016-9085 CVE-2016-8888 Upstream summary: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
SLES 15 — go — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 5 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-15041 CVE-2018-6574 CVE-2018-16873 CVE-2014-7189 CVE-2016-3959 CVE-2016-5386 CVE-2018-16874 CVE-2018-16875  +6 more Upstream summary: Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. […]

Read more
SLES 15 — hardlink — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — hardlink — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2011-3630 CVE-2011-3631 CVE-2011-3632 Upstream summary: Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote […]

Read more
CHAT