SLES

SLES 15 — python311-waitress — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-waitress — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 November 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3876-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-49768 CVE-2022-31015 Upstream summary: Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that […]

Read more
SLES 12 — less — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — less — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 November 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1534-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-32487 CVE-2022-48624 CVE-2014-9488 Upstream summary: less through 653 allows OS command execution via a newline character in the name of a file, because quoting is […]

Read more
SLES 15 — typelib — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — typelib — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 5 November 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9144 (see also SUSE bugzilla) Related CVEs: CVE-2024-4558 CVE-2022-0108 CVE-2021-33516 CVE-2017-1000121 CVE-2018-4437 CVE-2018-4438 CVE-2018-4441 CVE-2018-4442  +12 more Upstream summary: Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a […]

Read more
SLES 12 — kernel-rt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kernel-rt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 November 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2894-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-48791 CVE-2022-48911 CVE-2022-48945 CVE-2024-44987 CVE-2022-48822 CVE-2024-41062 CVE-2024-41087 CVE-2024-42232  +12 more Upstream summary: In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix […]

Read more
SLES 15 — kubernetes1.23-client — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — kubernetes1.23-client — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 October 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2292-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-25749 CVE-2021-25743 CVE-2024-3177 CVE-2024-0793 CVE-2022-3162 CVE-2022-3294 CVE-2023-2431 Upstream summary: Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. […]

Read more
SLES 15 — protobuf-devel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — protobuf-devel — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 October 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3745-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-7254 Upstream summary: Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted […]

Read more
SLES 12 — golang-github-prometheus-node_exporter — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — golang-github-prometheus-node_exporter — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 October 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3911-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-9264 CVE-2021-41244 CVE-2022-32149 CVE-2022-41723 CVE-2023-29409 CVE-2022-27664 CVE-2021-43798 CVE-2022-21698  +12 more Upstream summary: The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` […]

Read more
SLES 15 — rear23a — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rear23a — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 October 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0135-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-23301 Upstream summary: Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets […]

Read more
SLES 15 — python39 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python39 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 19 October 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-FU-2022:0444-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-15801 CVE-2022-42919 CVE-2021-29921 CVE-2020-15523 CVE-2024-8088 Upstream summary: In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from […]

Read more
SLES 15 — tpm2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tpm2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1605-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-29040 CVE-2023-22745 CVE-2020-24455 Upstream summary: This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned […]

Read more
CHAT