SLES

SLES 12 — libopenjp2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libopenjp2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 May 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1129-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-27823 CVE-2020-8112 CVE-2024-56826 CVE-2020-27824 CVE-2020-27842 CVE-2020-27843 CVE-2020-27845 CVE-2016-1924  +12 more Upstream summary: A flaw was found in OpenJPEG's encoder. This flaw allows an attacker to […]

Read more
SLES 15 — python2-sqlparse — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-sqlparse — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 May 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2024:1637-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-30608 Upstream summary: sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable […]

Read more
SLES 15 — gradle — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gradle — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 11 May 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1119-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-15052 CVE-2021-29428 CVE-2023-35947 CVE-2023-35946 CVE-2021-29429 CVE-2021-32751 CVE-2019-16370 Upstream summary: The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. […]

Read more
SLES 15 — python3-virtualenv — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-virtualenv — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 May 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10953 (see also SUSE bugzilla) Related CVEs: CVE-2024-53899 Upstream summary: virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when […]

Read more
SLES 12 — OpenIPMI — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — OpenIPMI — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8037 (see also SUSE bugzilla) Related CVEs: CVE-2024-42934 Upstream summary: OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with […]

Read more
SLES 15 — objectweb-asm — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — objectweb-asm — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 May 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2024:0560-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-37460 Upstream summary: Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. […]

Read more
SLES 12 — python-dnspython — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-dnspython — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 May 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9423 (see also SUSE bugzilla) Related CVEs: CVE-2023-29483 Upstream summary: eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an […]

Read more
SLES 12 — gimp — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gimp — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:0746 (see also SUSE bugzilla) Related CVEs: CVE-2023-44442 CVE-2023-44444 CVE-2022-32990 CVE-2022-30067 CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787  +11 more Upstream summary: GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability […]

Read more
SLES 12 — libraw9 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libraw9 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 30 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2300-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8367 CVE-2020-22628 CVE-2023-1729 CVE-2021-32142 CVE-2017-6889 CVE-2020-15503 CVE-2013-2126 CVE-2013-2127  +12 more Upstream summary: The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors […]

Read more
SLES 12 — libmicrohttpd10 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmicrohttpd10 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:1686-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-27371 CVE-2013-7038 CVE-2013-7039 Upstream summary: GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the […]

Read more
CHAT