SLES

SLES 15 — python3-scipy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-scipy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2970-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-29824 CVE-2023-25399 Upstream summary: A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that […]

Read more
SLES 15 — python2-Werkzeug — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-Werkzeug — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1572-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-34069 CVE-2023-25577 CVE-2019-14806 Upstream summary: Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to […]

Read more
SLES 15 — raptor — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — raptor — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2895-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-25713 CVE-2017-18926 CVE-2024-57822 CVE-2024-57823 CVE-2012-0037 Upstream summary: A malformed input file can lead to a segfault due to an out of bounds array access in […]

Read more
SLES 15 — libQt53DCore5 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libQt53DCore5 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2975-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-40724 Upstream summary: Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially […]

Read more
SLES 15 — librabbitmq4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — librabbitmq4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2823-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-35789 CVE-2019-18609 Upstream summary: An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered […]

Read more
SLES 12 — vorbis-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — vorbis-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4218-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-43361 CVE-2008-1686 CVE-2014-9638 CVE-2014-9639 CVE-2014-9640 CVE-2015-6749 Upstream summary: Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a […]

Read more
SLES 15 — tpm2.0-tools — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tpm2.0-tools — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9424 (see also SUSE bugzilla) Related CVEs: CVE-2024-29038 CVE-2024-29039 CVE-2021-3565 CVE-2017-7524 Upstream summary: tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote […]

Read more
SLES 12 — libhdf5-gnu-hpc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libhdf5-gnu-hpc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0538-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-4332 CVE-2018-13867 CVE-2018-17439 CVE-2021-37501 CVE-2021-45830 CVE-2021-45833 CVE-2021-46242 CVE-2024-29158  +12 more Upstream summary: The library's failure to check if certain message types support a particular flag, […]

Read more
SLES 15 — libgsf — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libgsf — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 April 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3770-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-36474 CVE-2024-42415 Upstream summary: An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library […]

Read more
SLES 12 — kgraft-patch — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kgraft-patch — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:0263-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-50756 CVE-2023-6546 CVE-2022-0886 CVE-2021-3573 CVE-2015-1421 CVE-2015-4700 CVE-2015-8019 CVE-2017-17053  +2 more Upstream summary: In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix mempool […]

Read more
CHAT