SLES

SLES 15 — liboqs7 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — liboqs7 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:0005-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-37305 CVE-2024-54137 CVE-2024-36405 Upstream summary: oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and […]

Read more
SLES 15 — xorg-x11-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xorg-x11-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1199-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-31082 CVE-2022-2319 CVE-2022-2320 CVE-2018-14665 CVE-2020-14345 CVE-2020-14346 CVE-2020-14360 CVE-2020-14361  +12 more Upstream summary: A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. […]

Read more
SLES 15 — less — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — less — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1534-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-32487 CVE-2022-48624 CVE-2022-46663 CVE-2014-9488 Upstream summary: less through 653 allows OS command execution via a newline character in the name of a file, because quoting […]

Read more
SLES 15 — frr — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — frr — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3426-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-15865 CVE-2024-44070 CVE-2024-34088 CVE-2024-31948 CVE-2024-31950 CVE-2024-31951 CVE-2023-47234 CVE-2023-47235  +12 more Upstream summary: bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in […]

Read more
SLES 15 — u-boot-tools — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — u-boot-tools — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2868-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-33103 CVE-2024-57256 CVE-2024-57258 CVE-2022-33967 CVE-2022-30767 CVE-2018-18439 CVE-2018-18440 Upstream summary: Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function […]

Read more
SLES 15 — python311-tqdm — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-tqdm — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2016-10075 CVE-2024-34062 Upstream summary: The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with […]

Read more
SLES 12 — perl-Crypt-OpenSSL-RSA — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-Crypt-OpenSSL-RSA — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 November 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:01884-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-2467 Upstream summary: A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style […]

Read more
SLES 12 — booth — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — booth — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 November 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2040-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-3049 CVE-2022-2553 Upstream summary: A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow […]

Read more
SLES 12 — python-Jinja2 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-Jinja2 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 November 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:0308 (see also SUSE bugzilla) Related CVEs: CVE-2024-56326 CVE-2016-10745 CVE-2019-10906 CVE-2019-8341 CVE-2020-28493 CVE-2024-34064 CVE-2014-0012 Upstream summary: Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed […]

Read more
SLES 15 — booth — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — booth — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 November 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2040-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-3049 CVE-2022-2553 Upstream summary: A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow […]

Read more
CHAT