SLES

SLES 15 — freeradius-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — freeradius-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory ESSA-2024:0650 (see also SUSE bugzilla) Related CVEs: CVE-2024-3596 CVE-2022-41860 CVE-2022-41861 CVE-2019-11235 CVE-2019-17185 CVE-2022-41859 CVE-2012-3547 CVE-2014-2015  +12 more Upstream summary: RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local […]

Read more
SLES 15 — apache-commons-fileupload — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache-commons-fileupload — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:14177 (see also SUSE bugzilla) Related CVEs: CVE-2025-48976 Upstream summary: Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons […]

Read more
SLES 15 — apache2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 23 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:2918-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-33193 CVE-2021-44790 CVE-2021-42013 CVE-2010-0425 CVE-2025-49630 CVE-2025-49812 CVE-2025-23048 CVE-2023-45802  +12 more Upstream summary: A crafted method sent through HTTP/2 will bypass validation and be forwarded by […]

Read more
SLES 15 — cni — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — cni — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1058-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-1753 CVE-2021-20206 CVE-2019-18466 Upstream summary: A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host […]

Read more
SLES 15 — redis — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — redis — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 22 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:19237 (see also SUSE bugzilla) Related CVEs: CVE-2025-46817 CVE-2025-46818 CVE-2025-46819 CVE-2025-49844 CVE-2016-8339 CVE-2018-11218 CVE-2018-11219 CVE-2025-32023  +12 more Upstream summary: Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 […]

Read more
SLES 15 — ghc-pandoc — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ghc-pandoc — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02037-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-38526 Upstream summary: pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc –math` linked to JavaScript files from polyfill[.]io. The polyfill[.]io CDN has […]

Read more
SLES 15 — apache-commons-lang — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache-commons-lang — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02785-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-48924 Upstream summary: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 […]

Read more
SLES 12 — libX11 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libX11 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 February 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2092-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-3138 CVE-2020-14363 CVE-2021-31535 CVE-2018-14600 CVE-2025-26597 CVE-2023-43785 CVE-2023-43786 CVE-2023-43787  +12 more Upstream summary: A vulnerability was found in libX11. The security flaw occurs because the functions […]

Read more
SLES 12 — libarchive13 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libarchive13 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 February 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:14130 (see also SUSE bugzilla) Related CVEs: CVE-2025-5914 CVE-2024-20696 CVE-2025-5916 CVE-2025-5917 CVE-2021-31566 CVE-2021-23177 CVE-2018-1000878 CVE-2019-18408  +12 more Upstream summary: A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() […]

Read more
SLES 12 — libtasn1 — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libtasn1 — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 18 February 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:2738-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-46848 CVE-2024-12133 CVE-2018-6003 CVE-2025-13151 CVE-2014-3467 CVE-2014-3468 CVE-2014-3469 CVE-2015-2806  +3 more Upstream summary: GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects […]

Read more
CHAT