SLES 15

SLES 15 — libgit2 — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libgit2 — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2584-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-24575 CVE-2023-22742 CVE-2018-15501 CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2016-8568 CVE-2016-8569  +6 more Upstream summary: libgit2 is a portable C implementation of the Git core methods provided as […]

Read more
SLES 15 — python3-scikit-learn — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-scikit-learn — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2029-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-5206 Upstream summary: A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in […]

Read more
SLES 15 — libcares2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcares2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1135-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-25629 CVE-2022-4904 CVE-2016-5180 CVE-2017-1000381 Upstream summary: c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as […]

Read more
SLES 15 — python2-gevent — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-gevent — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8834 (see also SUSE bugzilla) Related CVEs: CVE-2023-41419 Upstream summary: An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component. […]

Read more
SLES 15 — rage-encryption — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rage-encryption — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4060-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-42811 CVE-2023-22895 Upstream summary: aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES […]

Read more
SLES 15 — azure-cli — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — azure-cli — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 March 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:0751-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-43591 Upstream summary: Unknown. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution […]

Read more
SLES 15 — libtinyxml0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libtinyxml0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 March 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2021:1474-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-42260 CVE-2023-34194 Upstream summary: TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a […]

Read more
SLES 15 — exfatprogs — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — exfatprogs — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 March 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4449-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-45897 Upstream summary: exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
SLES 15 — libxerces-c — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libxerces-c — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 March 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8795 (see also SUSE bugzilla) Related CVEs: CVE-2023-37536 CVE-2018-1311 CVE-2017-12627 CVE-2009-1885 CVE-2016-0729 CVE-2016-2099 CVE-2016-4463 Upstream summary: An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access […]

Read more
SLES 15 — cpp7 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — cpp7 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3021-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-4039 CVE-2019-14250 CVE-2019-15847 CVE-2020-13844 Upstream summary: **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing […]

Read more
CHAT