SLES 15

SLES 15 — jawn-util — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — jawn-util — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 March 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2022:0011-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-21653 Upstream summary: Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash […]

Read more
SLES 15 — fish — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — fish — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 March 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2021:411-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-15257 CVE-2021-21285 CVE-2021-21284 Upstream summary: containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions […]

Read more
SLES 15 — testng — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — testng — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 February 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:1690-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-4065 CVE-2020-11022 CVE-2020-11023 Upstream summary: A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the […]

Read more
SLES 15 — crmsh — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — crmsh — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 February 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:0083-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-35459 CVE-2021-3020 Upstream summary: An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were […]

Read more
SLES 15 — libsass — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libsass — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 February 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4895-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-26592 CVE-2022-43357 CVE-2022-43358 Upstream summary: Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
SLES 15 — rpm — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rpm — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 February 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-7500 CVE-2021-3521 CVE-2021-3421 CVE-2021-20266 CVE-2021-20271 Upstream summary: It was found that rpm did not properly handle RPM installations when a destination path was a symbolic […]

Read more
SLES 15 — bcel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — bcel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 February 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:4306-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-42920 CVE-2022-34169 Upstream summary: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an […]

Read more
How to Set Up ModSecurity WAF on SLES 15 — step-by-step SUSE Linux Enterprise 15 tutorial on Progressive Robot

How to Set Up ModSecurity WAF on SLES 15

Introduction This tutorial covers How to Set Up ModSecurity WAF on SLES 15 on SLES 15. SLES 15 (SUSE Linux Enterprise Server 16) is SUSE’s enterprise-grade Linux distribution. It uses the zypper package manager, AppArmor for mandatory access control, and systemctl for service management. Prerequisites Ensure your SLES 15 system is up to date: zypper […]

Read more
How to Tune System Performance with tuned on SLES 15 — step-by-step SUSE Linux Enterprise 15 tutorial on Progressive Robot

How to Tune System Performance with tuned on SLES 15

Introduction This tutorial covers How to Tune System Performance with tuned on SLES 15 on SLES 15. SLES 15 (SUSE Linux Enterprise Server 16) is SUSE’s enterprise-grade Linux distribution. It uses the zypper package manager, AppArmor for mandatory access control, and systemctl for service management. Prerequisites Ensure your SLES 15 system is up to date: […]

Read more
CHAT