SLES 15

SLES 15 — libexif12 — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libexif12 — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 20 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:1534-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-13112 CVE-2020-0452 CVE-2019-9278 CVE-2020-13113 CVE-2020-0181 CVE-2020-0198 CVE-2012-2812 CVE-2012-2813  +11 more Upstream summary: An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF […]

Read more
SLES 15 — python2-pyOpenSSL — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-pyOpenSSL — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-FU-2022:0444-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4314 Upstream summary: The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name […]

Read more
SLES 15 — libImlib2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libImlib2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2010-0991 Upstream summary: Multiple heap-based buffer overflows in imlib2 1.4.3 allow context-dependent attackers to execute arbitrary code via a crafted (1) ARGB, (2) XPM, or […]

Read more
SLES 15 — libmwaw — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libmwaw — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1821-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-9433 Upstream summary: Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in […]

Read more
SLES 15 — libgme0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libgme0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:3250-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 Upstream summary: Stack-based buffer overflow in game-music-emu before 0.6.1. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
SLES 15 — python2-pycrypto — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-pycrypto — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2012:0869-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2417 CVE-2013-1445 CVE-2013-7459 Upstream summary: PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces […]

Read more
How to Deploy a Zend Framework Application on SLES 15 — step-by-step SUSE Linux Enterprise 15 tutorial on Progressive Robot

How to Deploy a Zend Framework Application on SLES 15

Introduction This tutorial covers How to Deploy a Zend Framework Application on SLES 15 on SLES 15. SLES 15 (SUSE Linux Enterprise Server 16) is SUSE’s enterprise-grade Linux distribution. It uses the zypper package manager, AppArmor for mandatory access control, and systemctl for service management. Prerequisites Ensure your SLES 15 system is up to date: […]

Read more
SLES 15 — system-user-root — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — system-user-root — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 6 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:697-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-5021 Upstream summary: Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to […]

Read more
SLES 15 — bsh2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — bsh2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:0699-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2510 Upstream summary: BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to […]

Read more
SLES 15 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 3 January 2020 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2058-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7705 CVE-2015-7853 CVE-2015-7871 CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 CVE-2014-9297  +12 more Upstream summary: The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 […]

Read more
CHAT