SLES 15

SLES 15 — unzip — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — unzip — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 June 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0026-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2014-9636 CVE-2018-1000035 CVE-2022-0529 CVE-2022-0530 CVE-2014-9913  +4 more Upstream summary: Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier […]

Read more
SLES 15 — apache-commons-configuration2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache-commons-configuration2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2022-33980 Upstream summary: Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where […]

Read more
SLES 15 — librbd1 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — librbd1 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:139-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-20288 CVE-2021-3509 CVE-2021-3531 CVE-2018-10861 CVE-2018-1128 CVE-2018-1129 CVE-2019-10222 CVE-2019-3821  +12 more Upstream summary: An authentication flaw was found in ceph in versions before 14.2.20. When the […]

Read more
How to Install Packer on SLES 15 — step-by-step SUSE Linux Enterprise 15 tutorial on Progressive Robot

How to Install Packer on SLES 15

Introduction This tutorial covers How to Install Packer on SLES 15 on SLES 15. SLES 15 (SUSE Linux Enterprise Server 16) is SUSE’s enterprise-grade Linux distribution. It uses the zypper package manager, AppArmor for mandatory access control, and systemctl for service management. Prerequisites Ensure your SLES 15 system is up to date: zypper refresh && […]

Read more
SLES 15 — python2-lxml — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-lxml — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:491-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-19787 CVE-2020-27783 CVE-2021-28957 CVE-2021-43818 Upstream summary: An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that […]

Read more
SLES 15 — ruby2.5-rubygem-loofah — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-loofah — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:1657-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-23514 CVE-2022-23516 CVE-2022-23515 CVE-2019-15587 Upstream summary: Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah […]

Read more
SLES 15 — python3-future — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-future — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0076-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-40899 Upstream summary: An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie […]

Read more
SLES 15 — python3-setuptools — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-setuptools — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:169-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-40897 Upstream summary: Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package […]

Read more
SLES 15 — swtpm — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — swtpm — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1101-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-23645 CVE-2020-28407 Upstream summary: swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 […]

Read more
SLES 15 — ruby2.5-rubygem-rails-html-sanitizer — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-rails-html-sanitizer — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 April 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3534-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-23518 CVE-2022-23519 CVE-2022-23517 CVE-2022-23520 CVE-2022-32209 Upstream summary: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to […]

Read more
CHAT