SLES

SLES 15 — go1.19 — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go1.19 — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 15 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1963-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-29402 CVE-2023-29404 CVE-2023-29405 CVE-2023-29409 CVE-2023-29403 CVE-2023-24539 CVE-2023-29400 CVE-2023-24534  +8 more Upstream summary: The go command may generate unexpected code at build time when using cgo. […]

Read more
SLES 12 — ovmf — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ovmf — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 13 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0579-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-12178 CVE-2023-45232 CVE-2023-45233 CVE-2023-45235 CVE-2022-36765 CVE-2023-45230 CVE-2023-45234 CVE-2021-38578  +12 more Upstream summary: Buffer overflow in network stack for EDK II may allow unprivileged user to […]

Read more
SLES 15 — wireshark — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — wireshark — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1347-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-24476 CVE-2024-2955 CVE-2024-0207 CVE-2024-0210 CVE-2024-0211 CVE-2024-0208 CVE-2024-0209 CVE-2023-2859  +12 more Upstream summary: A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause […]

Read more
SLES 12 — cloud-init — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cloud-init — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2021:6-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-8631 CVE-2020-8632 CVE-2021-3429 CVE-2023-1786 CVE-2019-0816 Upstream summary: cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to […]

Read more
SLES 15 — python312 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python312 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10978 (see also SUSE bugzilla) Related CVEs: CVE-2024-12254 CVE-2024-4030 CVE-2023-6507 Upstream summary: Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer […]

Read more
SLES 12 — unrar — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — unrar — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1975-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-33899 CVE-2022-30333 CVE-2017-12938 CVE-2017-12940 CVE-2017-12941 CVE-2017-12942 CVE-2017-20006 CVE-2012-6706 Upstream summary: RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen […]

Read more
SLES 15 — orc — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — orc — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:6184 (see also SUSE bugzilla) Related CVEs: CVE-2024-40897 Upstream summary: Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially […]

Read more
SLES 12 — drbd — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — drbd — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 June 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2960-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-1989 CVE-2023-1990 CVE-2023-2162 CVE-2023-1390 CVE-2023-28464 CVE-2023-28772 CVE-2023-1118 CVE-2023-0590  +12 more Upstream summary: A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. […]

Read more
SLES 15 — libgcrypt20 — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libgcrypt20 — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 June 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:254-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-33560 CVE-2015-5738 CVE-2021-3345 CVE-2024-2236 CVE-2021-40528 CVE-2013-4242 CVE-2014-3591 CVE-2015-0837  +6 more Upstream summary: Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks […]

Read more
CHAT