SLES

SLES 15 — ruby2.5-rubygem-actionmailer — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-actionmailer — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3878-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-47889 Upstream summary: Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and […]

Read more
SLES 15 — w3m — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — w3m — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 July 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4439-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-38252 CVE-2023-38253 CVE-2022-38223 CVE-2010-2074 CVE-2012-4929 CVE-2016-9434 CVE-2016-9435 CVE-2016-9436  +12 more Upstream summary: An out-of-bounds read flaw was found in w3m, in the Strnew_size function in […]

Read more
SLES 15 — pkgconf — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — pkgconf — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0611-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-24056 Upstream summary: In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file […]

Read more
SLES 12 — libgstapp — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgstapp — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:11123 (see also SUSE bugzilla) Related CVEs: CVE-2024-47538 CVE-2024-47607 CVE-2024-47615 CVE-2024-47541 CVE-2024-47542 CVE-2024-47613 CVE-2024-47835 Upstream summary: GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected […]

Read more
SLES 15 — libeditorconfig0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libeditorconfig0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:4152-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-53849 CVE-2023-0341 Upstream summary: editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may […]

Read more
SLES 12 — procps — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — procps — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1122 CVE-2018-1123 CVE-2018-1124 CVE-2018-1125 CVE-2018-1126 CVE-2023-4016 Upstream summary: procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs […]

Read more
SLES 15 — mdds — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — mdds — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4496-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-1183 Upstream summary: A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command […]

Read more
SLES 15 — libyang2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libyang2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2023-26916 Upstream summary: libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c. Table of contents […]

Read more
SLES 12 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 17 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2401-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-9855 CVE-2024-5261 CVE-2024-3044 CVE-2023-6185 CVE-2023-6186 CVE-2022-26305 CVE-2019-9852 CVE-2019-9854  +12 more Upstream summary: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which […]

Read more
SLES 12 — python-idna — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-idna — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8365 (see also SUSE bugzilla) Related CVEs: CVE-2024-3651 Upstream summary: A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's […]

Read more
CHAT