SLES

SLES 12 — libndp0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libndp0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 July 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2283-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-5564 CVE-2016-3698 Upstream summary: A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered […]

Read more
SLES 15 — cloud-init — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — cloud-init — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:10848 (see also SUSE bugzilla) Related CVEs: CVE-2024-6174 CVE-2020-8631 CVE-2020-8632 CVE-2024-11584 CVE-2021-3429 CVE-2022-2084 CVE-2023-1786 CVE-2019-0816 Upstream summary: When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with […]

Read more
SLES 15 — qatlib — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — qatlib — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:3942-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-28885 CVE-2024-31074 CVE-2024-33617 CVE-2023-22313 Upstream summary: Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network […]

Read more
SLES 15 — xmlgraphics-fop — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xmlgraphics-fop — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:4054-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-28168 Upstream summary: Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. […]

Read more
SLES 12 — freeradius-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — freeradius-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 July 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory ESSA-2024:0650 (see also SUSE bugzilla) Related CVEs: CVE-2024-3596 CVE-2022-41860 CVE-2022-41861 CVE-2019-17185 CVE-2019-11235 CVE-2022-41859 CVE-2019-13456 CVE-2012-3547  +12 more Upstream summary: RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local […]

Read more
SLES 15 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 13 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2401-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-9855 CVE-2024-5261 CVE-2024-3044 CVE-2023-6185 CVE-2023-6186 CVE-2022-26305 CVE-2019-9852 CVE-2019-9854  +12 more Upstream summary: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which […]

Read more
SLES 15 — texlive — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — texlive — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2019-18604 CVE-2023-32700 CVE-2016-10243 CVE-2018-17407 CVE-2020-8016 CVE-2020-8017 CVE-2023-46048 CVE-2023-46051 Upstream summary: In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and […]

Read more
SLES 15 — python311-GitPython — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-GitPython — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:14858-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24439 CVE-2023-40590 CVE-2023-40267 CVE-2023-41040 Upstream summary: All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which […]

Read more
SLES 12 — osc — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — osc — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 July 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2067-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-3685 CVE-2010-4226 CVE-2017-14804 CVE-2017-9274 CVE-2024-22034 CVE-2019-3681 CVE-2015-0778 CVE-2012-1095 Upstream summary: Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the […]

Read more
SLES 12 — libz1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libz1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 July 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1863-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-37434 CVE-2018-25032 CVE-2023-45853 Upstream summary: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header […]

Read more
CHAT