SLES 15

SLES 15 — libXvMC1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libXvMC1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 October 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1990 CVE-2013-1999 Upstream summary: Multiple integer overflows in X.org libXvMC 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer […]

Read more
SLES 15 — libpulse0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libpulse0 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0999-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-3970 Upstream summary: The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of […]

Read more
SLES 15 — pidgin — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — pidgin — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2009-2694 CVE-2010-0013 CVE-2011-3594 CVE-2012-6152 CVE-2017-2640 CVE-2009-2703 CVE-2009-3026 CVE-2009-3083  +12 more Upstream summary: The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) […]

Read more
SLES 15 — bogofilter-db — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — bogofilter-db — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:014 (see also SUSE bugzilla) Related CVEs: CVE-2010-2494 CVE-2012-5468 Upstream summary: Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote […]

Read more
SLES 15 — nasm — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — nasm — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:1843-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-19214 CVE-2018-19215 CVE-2017-10686 CVE-2017-14228 CVE-2017-17810 CVE-2018-16382 CVE-2018-1000667 CVE-2018-10016  +12 more Upstream summary: Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c […]

Read more
SLES 15 — libserf — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libserf — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-3504 Upstream summary: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL […]

Read more
SLES 15 — podofo — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — podofo — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3541-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8981 CVE-2017-6840 CVE-2017-6841 CVE-2017-6842 CVE-2017-6845 CVE-2017-6849 CVE-2017-8378 CVE-2018-5309  +6 more Upstream summary: Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers […]

Read more
SLES 15 — ppc64-diag — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ppc64-diag — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0928-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-4038 CVE-2014-4039 Upstream summary: ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc […]

Read more
SLES 15 — gettext-tools — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gettext-tools — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2020:117-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-18751 Upstream summary: An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free […]

Read more
SLES 15 — librelp0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — librelp0 — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 September 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:0822-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1000140 Upstream summary: rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can […]

Read more
CHAT