SLES 15

SLES 15 — apache2-mod_jk — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache2-mod_jk — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:3963-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-11759 CVE-2023-41081 CVE-2024-46544 CVE-2008-5519 CVE-2014-8111 CVE-2018-1323 Upstream summary: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the […]

Read more
SLES 15 — supportutils-plugin-salt — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — supportutils-plugin-salt — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2024:4008-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-22037 Upstream summary: The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment […]

Read more
SLES 15 — liblasso3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — liblasso3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 8 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:21452 (see also SUSE bugzilla) Related CVEs: CVE-2025-47151 CVE-2025-46784 CVE-2025-46404 CVE-2025-46705 CVE-2021-28091 Upstream summary: A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted […]

Read more
SLES 15 — python311-pycares — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-pycares — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03354-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-48945 Upstream summary: pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and name […]

Read more
SLES 15 — go1.21 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go1.21 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0800-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-45289 CVE-2023-45290 CVE-2024-24783 CVE-2024-24784 CVE-2024-24785 CVE-2023-39320 CVE-2023-39321 CVE-2023-39322  +4 more Upstream summary: When following an HTTP redirect to a domain which is not a subdomain […]

Read more
SLES 15 — clamav — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — clamav — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 31 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0453-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-20032 CVE-2010-1205 CVE-2025-20260 CVE-2024-20505 CVE-2024-20380 CVE-2023-40477 CVE-2023-20197 CVE-2022-20771  +12 more Upstream summary: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was […]

Read more
SLES 15 — kubevirt-virtctl — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — kubevirt-virtctl — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:4330-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-64324 CVE-2023-26484 CVE-2022-1798 CVE-2025-64432 CVE-2025-64433 CVE-2025-64434 CVE-2025-64435 CVE-2024-33394  +1 more Upstream summary: KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in […]

Read more
SLES 15 — ghostscript — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ghostscript — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 27 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:3044-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3781 CVE-2025-27832 CVE-2025-27835 CVE-2025-27836 CVE-2024-46951 CVE-2024-46953 CVE-2024-46956 CVE-2020-16305  +12 more Upstream summary: A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in […]

Read more
SLES 15 — ruby2.5-rubygem-rack — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-rack — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2192-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-30123 CVE-2025-61919 CVE-2025-27610 CVE-2024-25126 CVE-2024-26141 CVE-2025-61780 CVE-2025-25184 CVE-2025-27111  +9 more Upstream summary: A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could […]

Read more
SLES 15 — ruby2.5-rubygem-puma — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-puma — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3957-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-40175 CVE-2022-24790 CVE-2021-29509 CVE-2024-21647 CVE-2024-45614 CVE-2022-23634 CVE-2021-41136 Upstream summary: Puma is a Ruby/Rack web server built for parallelism. Prior to versions 6.3.1 and 5.6.7, puma […]

Read more
CHAT