SLES

SLES 12 — python-WebOb — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-WebOb — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2969-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-42353 Upstream summary: WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does […]

Read more
SLES 12 — openssh8.4 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — openssh8.4 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 March 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:23479 (see also SUSE bugzilla) Related CVEs: CVE-2025-61985 Upstream summary: ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is […]

Read more
SLES 12 — quagga — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — quagga — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 13 March 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:0455-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-5379 CVE-2017-15865 CVE-2022-37032 CVE-2024-44070 CVE-2023-38802 CVE-2023-41358 CVE-2018-5381 CVE-2018-5378  +8 more Upstream summary: The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when […]

Read more
SLES 15 — python2-future — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-future — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03028-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-50817 Upstream summary: A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When […]

Read more
SLES 15 — python311-zipp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-zipp — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-202410:15282-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-5569 Upstream summary: A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when […]

Read more
SLES 15 — libjasper4 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libjasper4 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1396-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-31744 CVE-2015-5203 CVE-2015-5221 CVE-2016-1577 CVE-2016-8654 CVE-2016-9262 CVE-2016-9560 CVE-2020-27828  +12 more Upstream summary: In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, […]

Read more
SLES 15 — krb5 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — krb5 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 11 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2010:006 (see also SUSE bugzilla) Related CVEs: CVE-2009-4212 CVE-2024-37370 CVE-2024-26458 CVE-2024-26462 CVE-2023-36054 CVE-2002-2443 CVE-2009-0846 CVE-2009-0847  +12 more Upstream summary: Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in […]

Read more
SLES 12 — fontforge — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — fontforge — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 March 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:4267 (see also SUSE bugzilla) Related CVEs: CVE-2024-25081 CVE-2024-25082 CVE-2020-25690 CVE-2020-5395 CVE-2020-5496 CVE-2017-11568 CVE-2017-11569 CVE-2017-11570  +7 more Upstream summary: Splinefont in FontForge through 20230101 allows command injection via crafted filenames. Table of […]

Read more
SLES 15 — python2-waitress — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-waitress — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3876-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-49769 CVE-2022-24761 CVE-2019-16785 CVE-2019-16786 CVE-2019-16789 CVE-2019-16792 Upstream summary: Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client […]

Read more
CHAT