SLES 15

SLES 15 — libproxy1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libproxy1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 March 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2020:518-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-25219 CVE-2020-26154 CVE-2012-4504 Upstream summary: url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response […]

Read more
SLES 15 — spamassassin — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — spamassassin — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 March 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1961-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-15705 CVE-2018-11780 CVE-2018-11781 CVE-2018-11805 CVE-2019-12420 CVE-2020-1930 CVE-2020-1931 CVE-2020-1946 Upstream summary: A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The […]

Read more
SLES 15 — glib-networking — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — glib-networking — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:3944-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-13645 Upstream summary: In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to […]

Read more
SLES 15 — rust-cbindgen — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rust-cbindgen — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 26 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:14826-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-32810 CVE-2021-29980 CVE-2021-29985 CVE-2021-29986 CVE-2021-29988 CVE-2021-29989 CVE-2021-29990 CVE-2021-29991  +11 more Upstream summary: crossbeam-deque is a package of work-stealing deques for building task schedulers when programming […]

Read more
SLES 15 — linuxptp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — linuxptp — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:2443-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3570 Upstream summary: A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between […]

Read more
SLES 15 — libonig4 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libonig4 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2022:1093-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-19203 CVE-2019-19204 CVE-2019-19246 CVE-2019-13225 CVE-2019-13224 CVE-2019-16163 CVE-2020-26159 Upstream summary: An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, […]

Read more
SLES 15 — libzmq5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libzmq5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-FU-2022:0444-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-13132 CVE-2019-6250 CVE-2020-15166 CVE-2014-7202 CVE-2014-7203 CVE-2014-9721 Upstream summary: In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting […]

Read more
SLES 15 — zsh — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — zsh — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:0732-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-20044 CVE-2021-45444 CVE-2018-0502 CVE-2018-1100 CVE-2018-13259 CVE-2018-1083 CVE-2018-1071 Upstream summary: In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the –no-PRIVILEGED […]

Read more
SLES 15 — libblas3 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libblas3 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:0913-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-4048 Upstream summary: An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used […]

Read more
SLES 15 — squashfs — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — squashfs — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 February 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4424-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-40153 CVE-2021-41072 CVE-2015-4645 CVE-2015-4646 CVE-2012-4025 CVE-2012-4024 Upstream summary: squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used […]

Read more
CHAT