SLES 15

SLES 15 — hdf5 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — hdf5 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0691-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-37501 CVE-2018-13867 CVE-2018-17439 CVE-2021-45830 CVE-2021-45833 CVE-2021-46242 CVE-2018-11205 CVE-2018-14031  +4 more Upstream summary: Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause […]

Read more
SLES 15 — qpdf — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — qpdf — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2669-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-36978 CVE-2017-11624 CVE-2017-11625 CVE-2017-11627 CVE-2022-34503 CVE-2017-9208 CVE-2017-9209 CVE-2017-9210  +2 more Upstream summary: QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow […]

Read more
SLES 15 — go1.18 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go1.18 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1897-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-41724 CVE-2022-41717 CVE-2022-41720 CVE-2022-2879 CVE-2022-2880 CVE-2022-41725 CVE-2022-41716 CVE-2022-27536 Upstream summary: Large handshake records may cause panics in crypto/tls. Both clients and servers may send large […]

Read more
SLES 15 — hawk2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — hawk2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 9 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:0088-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-35458 CVE-2021-25314 Upstream summary: An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id […]

Read more
SLES 15 — libcaca0 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcaca0 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 7 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:0754-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-30498 CVE-2021-30499 CVE-2022-0856 CVE-2021-3410 CVE-2018-20547 CVE-2018-20544 CVE-2018-20545 CVE-2018-20546  +2 more Upstream summary: A flaw was found in libcaca. A heap buffer overflow in export.c in […]

Read more
SLES 15 — fribidi — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — fribidi — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:233-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-18397 CVE-2022-25308 CVE-2022-25309 CVE-2022-25310 Upstream summary: A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause […]

Read more
SLES 15 — ruby2.5-rubygem-activerecord — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-activerecord — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0492-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-44566 CVE-2021-22880 Upstream summary: A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a […]

Read more
How to Secure MySQL on SLES 15 — step-by-step SUSE Linux Enterprise 15 tutorial on Progressive Robot

How to Secure MySQL on SLES 15

Introduction This tutorial covers How to Secure MySQL on SLES 15 on SLES 15. SLES 15 (SUSE Linux Enterprise Server 16) is SUSE’s enterprise-grade Linux distribution. It uses the zypper package manager, AppArmor for mandatory access control, and systemctl for service management. Prerequisites Ensure your SLES 15 system is up to date: zypper refresh && […]

Read more
SLES 15 — librav1e0_6 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — librav1e0_6 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 June 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:3015-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-45710 CVE-2018-25023 Upstream summary: An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances […]

Read more
SLES 15 — mozilla-nspr — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — mozilla-nspr — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 June 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1926-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7183 CVE-2020-15673 CVE-2020-15676 CVE-2020-15677 CVE-2020-15678 CVE-2020-15683 CVE-2020-15969 CVE-2021-23981  +4 more Upstream summary: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla […]

Read more
CHAT