SLES 15

SLES 15 — zbar — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — zbar — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 September 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4948-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-40889 CVE-2023-40890 Upstream summary: A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure […]

Read more
SLES 15 — libmfx1 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libmfx1 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 September 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3198-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22656 CVE-2023-45221 CVE-2023-47169 CVE-2023-47282 CVE-2023-48368 Upstream summary: Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated […]

Read more
SLES 15 — xmlsec1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xmlsec1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 August 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-FU-2023:3413-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-0950 CVE-2023-2255 Upstream summary: Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a […]

Read more
SLES 15 — ruby2.5-rubygem-activesupport — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-activesupport — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0275-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22796 Upstream summary: A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can […]

Read more
SLES 15 — cmark — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — cmark — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:1834-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22486 Upstream summary: cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a […]

Read more
SLES 15 — python3-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 11 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2561-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-33733 CVE-2019-17626 CVE-2019-19450 CVE-2020-28463 Upstream summary: Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. Table of contents […]

Read more
SLES 15 — supportutils — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — supportutils — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0480-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-19637 CVE-2018-19639 CVE-2022-45154 CVE-2018-19640 CVE-2018-19638 Upstream summary: Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems […]

Read more
SLES 15 — python2-PyJWT — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-PyJWT — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1736-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-29217 Upstream summary: PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT […]

Read more
SLES 15 — libeconf0 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libeconf0 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3064-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22652 CVE-2023-30078 CVE-2023-30079 CVE-2023-32181 Upstream summary: A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via […]

Read more
SLES 15 — telnet — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — telnet — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3471-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-39028 Upstream summary: telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or […]

Read more
CHAT