SLES 15

SLES 15 — python2-WebOb — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-WebOb — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2969-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-42353 Upstream summary: WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does […]

Read more
SLES 15 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1161-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24070 CVE-2017-9800 CVE-2019-0203 CVE-2020-17525 CVE-2024-46901 CVE-2021-28544 CVE-2009-2411 CVE-2010-3315  +12 more Upstream summary: Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, […]

Read more
SLES 15 — zypper — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — zypper — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-7685 CVE-2017-7436 CVE-2017-9269 CVE-2017-9271 CVE-2018-20532 CVE-2018-20533 CVE-2019-18900 CVE-2024-0217  +1 more Upstream summary: The decoupled download and installation steps in libzypp before 17.5.0 could lead to […]

Read more
SLES 15 — libzypp-plugin-appdata — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libzypp-plugin-appdata — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0095-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22643 Upstream summary: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux Enterprise Server […]

Read more
SLES 15 — libavif13 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libavif13 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 December 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0423-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-6704 Upstream summary: Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a […]

Read more
SLES 15 — dbus — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — dbus — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 December 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:263-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-35512 CVE-2012-3524 CVE-2023-34969 CVE-2022-42011 CVE-2022-42012 CVE-2020-12049 CVE-2010-1172 CVE-2013-0292  +12 more Upstream summary: A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable […]

Read more
SLES 15 — python2-requests — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-requests — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2518-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-32681 CVE-2018-18074 CVE-2014-1829 CVE-2014-1830 Upstream summary: Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected […]

Read more
SLES 15 — libre2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libre2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0573-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-32731 Upstream summary: When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any […]

Read more
SLES 15 — wpa_supplicant — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — wpa_supplicant — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:0504-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-23303 CVE-2022-23304 CVE-2019-9494 CVE-2019-9498 CVE-2019-9499 CVE-2021-0326 CVE-2021-27803 CVE-2023-52424  +12 more Upstream summary: The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are […]

Read more
SLES 15 — python311-cmarkgfm — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-cmarkgfm — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2023-37463 Upstream summary: cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three […]

Read more
CHAT