SLES

SLES 15 — python3-idna — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-idna — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 August 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8365 (see also SUSE bugzilla) Related CVEs: CVE-2024-3651 Upstream summary: A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's […]

Read more
SLES 15 — wxQt — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — wxQt — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 August 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:01735-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-58249 Upstream summary: In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. Table of contents Symptom […]

Read more
SLES 12 — google-guest-agent — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — google-guest-agent — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 August 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:01985-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-45337 CVE-2022-23806 CVE-2021-38297 Upstream summary: Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for […]

Read more
SLES 12 — apache-commons-io — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — apache-commons-io — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 August 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2025:1150-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-47554 CVE-2021-29425 Upstream summary: Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. […]

Read more
SLES 15 — python311-tornado6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-tornado6 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 August 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10590 (see also SUSE bugzilla) Related CVEs: CVE-2024-52804 Upstream summary: Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to […]

Read more
SLES 15 — python3-pymongo — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-pymongo — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 August 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1571-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-21506 Upstream summary: Duplicate of CVE-2024-5629. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary […]

Read more
SLES 12 — pcp — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pcp — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 August 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3533-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-3019 CVE-2019-3695 CVE-2019-3696 CVE-2023-6917 CVE-2024-45769 CVE-2024-45770 CVE-2020-8025 CVE-2012-3418  +4 more Upstream summary: A flaw was found in PCP. The default pmproxy configuration exposes the Redis […]

Read more
SLES 15 — python3-gunicorn — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-gunicorn — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 August 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:1002-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-6827 CVE-2024-1135 Upstream summary: Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads […]

Read more
SLES 15 — openjpeg2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — openjpeg2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 August 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1252-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-6851 CVE-2020-8112 CVE-2017-14151 CVE-2017-14152 CVE-2020-27823 CVE-2024-56826 CVE-2018-20846 CVE-2020-27824  +12 more Upstream summary: OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because […]

Read more
SLES 12 — libraptor2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libraptor2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 July 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03244-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-57822 CVE-2024-57823 Upstream summary: In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in […]

Read more
CHAT