SLES

SLES 15 — gawk — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gawk — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 March 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2768-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-4156 Upstream summary: A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could […]

Read more
SLES 12 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 February 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9243 (see also SUSE bugzilla) Related CVEs: CVE-2023-51764 CVE-2023-32182 Upstream summary: Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). […]

Read more
SLES 12 — libslurm39 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libslurm39 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 February 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0280-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-49935 Upstream summary: An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. […]

Read more
SLES 15 — python3-uamqp — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-uamqp — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 23 February 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0323-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-21646 CVE-2024-27099 CVE-2024-25110 Upstream summary: Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to […]

Read more
SLES 15 — perl-Spreadsheet-ParseExcel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — perl-Spreadsheet-ParseExcel — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 February 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0158-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-7101 Upstream summary: Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability […]

Read more
SLES 15 — libgrpc8 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libgrpc8 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 February 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0573-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-33953 CVE-2022-3171 CVE-2021-22569 Upstream summary: gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in […]

Read more
SLES 15 — vorbis-tools — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — vorbis-tools — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 February 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4218-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-43361 CVE-2014-9638 CVE-2014-9639 CVE-2014-9640 CVE-2015-6749 Upstream summary: Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial […]

Read more
SLES 15 — libqb20 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libqb20 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3727-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-39976 Upstream summary: log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered. Table of […]

Read more
SLES 12 — opensc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — opensc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 February 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:3582-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-42781 CVE-2021-42782 CVE-2023-5992 CVE-2023-40661 CVE-2023-2977 CVE-2019-15945 CVE-2019-15946 CVE-2019-19479  +12 more Upstream summary: Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c […]

Read more
SLES 15 — go1.20 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go1.20 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 February 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:4104-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-39326 CVE-2023-39325 CVE-2023-39323 CVE-2023-45285 CVE-2023-45283 CVE-2023-45284 CVE-2023-39318 CVE-2023-39319 Upstream summary: A malicious HTTP sender can use chunk extensions to cause a receiver reading from a […]

Read more
CHAT