SLES

SLES 12 — typelib — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — typelib — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 10 October 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9144 (see also SUSE bugzilla) Related CVEs: CVE-2024-4558 CVE-2022-0108 CVE-2021-1765 CVE-2021-1788 CVE-2021-1789 CVE-2021-1799 CVE-2021-1801 CVE-2021-1844  +12 more Upstream summary: Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a […]

Read more
SLES 15 — pcp — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — pcp — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 October 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3533-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-3019 CVE-2019-3695 CVE-2019-3696 CVE-2023-6917 CVE-2024-45769 CVE-2024-45770 CVE-2012-3418 CVE-2012-3419  +4 more Upstream summary: A flaw was found in PCP. The default pmproxy configuration exposes the Redis […]

Read more
SLES 15 — libQt5Gui5 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libQt5Gui5 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 4 October 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2020-12267 CVE-2024-39936 CVE-2023-32763 CVE-2023-24607 CVE-2022-23853 CVE-2022-25255 CVE-2020-24741 CVE-2020-0569  +12 more Upstream summary: setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock. Table of […]

Read more
SLES 15 — python3-Jinja2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-Jinja2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 September 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1863-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-22195 CVE-2024-34064 Upstream summary: Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible […]

Read more
SLES 15 — npm16 — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — npm16 — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 September 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1678-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-32067 CVE-2023-23919 CVE-2023-24807 CVE-2022-35255 CVE-2024-30261 CVE-2024-24758 CVE-2023-39333 CVE-2023-30588  +11 more Upstream summary: c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. […]

Read more
SLES 12 — libzzip — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libzzip — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 September 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2925-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-39134 CVE-2020-18442 CVE-2017-5974 CVE-2017-5975 CVE-2017-5976 CVE-2017-5977 CVE-2017-5978 CVE-2017-5979  +12 more Upstream summary: A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a […]

Read more
SLES 15 — docker — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — docker — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 September 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2024:4391-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-41110 CVE-2023-47108 CVE-2023-45142 CVE-2024-24786 CVE-2024-3727 CVE-2024-23651 CVE-2024-23653 CVE-2023-28840  +12 more Upstream summary: Moby is an open-source project created by Docker for software containerization. A security […]

Read more
SLES 12 — pam — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 September 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10379 (see also SUSE bugzilla) Related CVEs: CVE-2024-10041 CVE-2024-22365 CVE-2010-3430 CVE-2010-3431 CVE-2010-3853 CVE-2011-3148 CVE-2014-2583 CVE-2015-3238  +1 more Upstream summary: A vulnerability was found in PAM. The secret information is stored in memory, […]

Read more
SLES 12 — subversion-devel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — subversion-devel — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 August 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:4366-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-46901 Upstream summary: Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit […]

Read more
SLES 12 — libgtk — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgtk — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 August 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:6963 (see also SUSE bugzilla) Related CVEs: CVE-2024-6655 Upstream summary: A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a […]

Read more
CHAT