SLES 15

SLES 15 — libxmltooling9 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libxmltooling9 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2766-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-36661 Upstream summary: Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed […]

Read more
SLES 15 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9243 (see also SUSE bugzilla) Related CVEs: CVE-2023-51764 CVE-2023-32182 Upstream summary: Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). […]

Read more
SLES 15 — libcryptopp8_6_0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcryptopp8_6_0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:4310-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-50979 CVE-2023-50981 CVE-2023-50980 CVE-2019-14318 CVE-2021-40530 Upstream summary: Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding. Table of […]

Read more
SLES 15 — opensc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — opensc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 November 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4089-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-40660 CVE-2021-42781 CVE-2021-42782 CVE-2023-5992 CVE-2023-40661 CVE-2023-2977 CVE-2021-42779 CVE-2019-19481  +12 more Upstream summary: A flaw was found in OpenSC packages that allow a potential PIN bypass. […]

Read more
SLES 15 — cpio — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — cpio — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 October 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:283-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-38185 CVE-2023-7207 CVE-2014-9112 CVE-2016-2037 CVE-2019-14866 CVE-2015-1197 Upstream summary: GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of […]

Read more
SLES 15 — libva2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libva2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 October 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:1451-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-39929 Upstream summary: Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation […]

Read more
SLES 15 — shim — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — shim — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 October 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory ESSA-2025:0001 (see also SUSE bugzilla) Related CVEs: CVE-2023-40547 CVE-2022-28737 CVE-2020-10713 CVE-2023-40546 CVE-2023-40548 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551  +4 more Upstream summary: A remote code execution vulnerability was found in Shim. The Shim boot support […]

Read more
SLES 15 — libvpx7 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libvpx7 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 October 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2409-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-44488 Upstream summary: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. Table of contents Symptom & Impact Environment & […]

Read more
SLES 15 — traceroute — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — traceroute — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 October 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3924-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-46316 Upstream summary: In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines. Table of contents Symptom & […]

Read more
SLES 15 — npm10 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — npm10 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 26 September 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:2824-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-22940 CVE-2022-25881 CVE-2023-23920 CVE-2022-43548 CVE-2022-32212 CVE-2021-22931 CVE-2021-3672 CVE-2020-1971  +12 more Upstream summary: Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free […]

Read more
CHAT