SLES 15

SLES 15 — jgit — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — jgit — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 July 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0057-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-4759 CVE-2025-4949 Upstream summary: Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a […]

Read more
SLES 15 — gdm — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gdm — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 July 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2025:20479-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-6018 CVE-2020-16125 CVE-2011-1709 CVE-2017-12164 CVE-2018-14424 CVE-2019-3825 CVE-2020-27837 CVE-2015-7496 Upstream summary: A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication […]

Read more
SLES 15 — xrdp — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xrdp — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 July 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:0404-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-68670 CVE-2024-39917 CVE-2022-23477 CVE-2020-4044 CVE-2023-42822 CVE-2023-40184 CVE-2022-23478 CVE-2022-23468  +10 more Upstream summary: xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated […]

Read more
SLES 15 — libcjson1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcjson1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03520-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-57052 CVE-2023-26819 Upstream summary: cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking […]

Read more
SLES 15 — gnome-settings-daemon — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gnome-settings-daemon — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 July 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2168-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-38394 CVE-2014-7300 Upstream summary: Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic […]

Read more
SLES 15 — ongres-scram — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ongres-scram — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 July 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:21016-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-59432 CVE-2022-26520 Upstream summary: SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication […]

Read more
SLES 15 — proftpd — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — proftpd — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 2 July 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2019:1836-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-12815 CVE-2019-19270 CVE-2020-9272 CVE-2020-9273 CVE-2023-51713 CVE-2024-48651 CVE-2015-3306 CVE-2016-3125  +4 more Upstream summary: An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows […]

Read more
SLES 15 — dpkg — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — dpkg — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 June 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02734-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-6297 CVE-2022-1664 CVE-2015-0840 Upstream summary: It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, […]

Read more
SLES 15 — p7zip — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — p7zip — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 June 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2475-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-52168 CVE-2023-52169 CVE-2017-17969 CVE-2022-47069 CVE-2023-1576 CVE-2025-53817 CVE-2021-3465 CVE-2016-2334  +3 more Upstream summary: The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based […]

Read more
SLES 15 — python311-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 June 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:15608 (see also SUSE bugzilla) Related CVEs: CVE-2024-26130 CVE-2023-38325 Upstream summary: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to […]

Read more
CHAT